T09 · Insecure Skill Coding Practices
- Location
SKILL.md:130- Finding
Unrestricted Local File Upload to Slack
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 130-138
Vulnerability Type: Arbitrary local file disclosure through an external service
Risk Level: Highpython def upload_file(self, channel_id: str, filepath: str, title: str = ""): """上传文件到频道""" with open(filepath, "rb") as f: resp = self.client.files_upload_v2( channel=channel_id, file=f, title=title or os.path.basename(filepath) ) return resp["file"]["permalink"]Technical Analysis
The upload function accepts a caller-controlled
filepath, opens that path without validation, and transmits the file to Slack. It does not restrict access to an approved directory, reject absolute paths or traversal sequences, detect symbolic links, screen sensitive filenames, enforce size limits, or request confirmation before transmission.Uploading files is part of the declared functionality, but unrestricted access to the host filesystem is broader than necessary. In an agent context, prompt injection or an incorrect user request could cause the helper to upload credentials, environment files, private keys, application configuration, source code, or sensitive logs.
Attack Path
- An attacker supplies an instruction through user input or other untrusted content that influences the
filepathand destination channel. - The instruction selects a sensitive path such as
.env, a credential file, an SSH key, or a private application log. - The function opens the selected file with
open(filepath, "rb"). files_upload_v2transmits the complete file to the chosen Slack channel.- Anyone with access to that channel or the resulting Slack file can retrieve the exposed information.
Impact Assessment
Exploitation can disclose any file readable by the process running the Skill. The effective scope therefore inherits the host process's filesystem privileges. Exposed crede ...[truncated 256 chars]
- An attacker supplies an instruction through user input or other untrusted content that influences the
- Remediation
View remediation
Remediation Suggestions
- Restrict uploads to a dedicated, explicitly configured export directory.
- Canonicalize the requested path with
realpathorPath.resolve()and verify that it remains beneath the approved directory. - Reject absolute paths, traversal outside the approved root, symbolic links, device files, sockets, and other non-regular files.
- Deny sensitive filename and directory patterns such as
.env, credential stores, private keys, browser profiles, and cloud configuration. - Enforce file-type and size limits before opening or transmitting content.
- Require explicit user confirmation that displays the resolved source path and destination channel.
- Apply destination-channel allowlists where practical.
- Run the Skill under a dedicated account with minimal filesystem permissions.
- Record security-safe audit metadata without logging file contents or credentials.
