T09 · Insecure Skill Coding Practices
- Location
SKILL.md:8- Finding
Dry-Run Safety Control Is Declared but Not Enforced
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–19
Vulnerability Type: Missing enforcement of a filesystem safety control
Risk Level: MediumVulnerable Instruction Snippet
The following is an English translation of the complete relevant instruction segment:
markdown ## Parameters - dry_run: Boolean, defaults to true. If true, only preview and do not perform actual operations. ## Execution Flow 1. Obtain the Desktop path (Windows: ~/Desktop, macOS/Linux: ~/Desktop) 2. List all files, excluding .DS_Store and shortcuts 3. Classify by extension: - Images: .jpg, .png, .gif → move to Desktop/Images - Documents: .pdf, .docx, .txt → move to Desktop/Documents - Archives: .zip, .rar → move to Desktop/Archives 4. Generate an operation report informing the user which files were movedTechnical Analysis
The skill declares that
dry_rundefaults totrueand that this mode must only preview operations. However, the execution flow contains no conditional step requiring the agent to evaluatedry_runbefore creating directories or moving files. Instead, it proceeds directly from file enumeration to instructions to move matching files.This is a fail-open design: the documented safety parameter exists, but the operative instructions do not bind filesystem mutations to
dry_run=false. An agent following the execution flow literally could therefore perform real file moves during the default preview-only mode.The issue does not demonstrate command injection, privilege escalation, or malicious intent. It is an insecure skill-control implementation because a promised safeguard against unintended filesystem modification is not enforced.
Attack Path
- A user invokes the Desktop organization skill without explicitly setting
dry_run. - According to the parameter definition,
dry_runassumes its default value oftrue. - The agent enumerates files from the user's Des ...[truncated 1279 chars]
- A user invokes the Desktop organization skill without explicitly setting
- Remediation
View remediation
Remediation Suggestions
- Add an explicit conditional branch before every mutating operation:
- When
dry_run=true, only enumerate files and report proposed source and destination paths. - When
dry_run=false, allow directory creation and file movement.
- When
- Require explicit user confirmation before executing the non-dry-run plan, especially when multiple files will be moved.
- Ensure that destination directories are not created during dry-run mode because directory creation is also a filesystem mutation.
- Define deterministic collision handling. Never overwrite an existing destination file silently; instead, skip the file, request confirmation, or generate a unique filename.
- Quote and validate all paths if the workflow is implemented with shell commands. Use argument arrays or equivalent safe filesystem APIs rather than constructing commands through string concatenation.
- Generate the report from actual operation results. In dry-run mode, label entries as proposed moves rather than completed moves.
- Add test cases verifying that the default invocation performs no writes, directory creation, renaming, or movement.
- Add an explicit conditional branch before every mutating operation:
