T09 · Insecure Skill Coding Practices
- Location
SKILL.md:12- Finding
Predictable Global Temporary-Directory Lock Enables Local Denial of Service
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-16
Vulnerability Type: Predictable and unmanaged temporary lock
Risk Level: MediumVulnerable Code Snippet
markdown The skill is triggered when a group message contains the configured mention and `/tmp/design-framework-lock` does not exist. ## Execution Process 1. **Atomic lock**: `mkdir /tmp/design-framework-lock` to prevent concurrent execution.The snippet above is an English rendering of the documented behavior at the cited location. The security-relevant literal path and command are reproduced exactly.
Technical Analysis
The skill uses the fixed, system-wide path
/tmp/design-framework-lockboth as a trigger condition and as its concurrency lock. Althoughmkdirprovides atomic creation, the documentation does not specify:- Validation of the directory's owner or permissions.
- A private, owner-restricted runtime directory.
- A process identifier or other mechanism for determining whether the lock is active.
- Stale-lock detection and recovery.
- Guaranteed cleanup through a shell
trapor equivalent mechanism.
On a multi-user host, another local process may create this predictable path before the skill runs. Because the absence of that path is explicitly required for triggering, pre-creation can prevent legitimate jobs from starting. A worker crash can also leave the directory behind and cause a persistent denial of service until manual cleanup.
This issue does not provide additional operating-system privileges. Exploitation requires sufficient local filesystem access to create an entry under
/tmp.Attack Path
- An attacker or untrusted local process creates
/tmp/design-framework-lock. - A legitimate Telegram message containing the configured mention arrives.
- The skill checks whether the fixed lock path exists.
- Because the attacker-created directory already exists, the trigger condition fails ...[truncated 613 chars]
- Remediation
View remediation
Remediation Suggestions
- Store runtime locks in an owner-restricted directory such as
$XDG_RUNTIME_DIR/design-framework-builder/, with permissions set to0700. - Prefer an advisory lock using
flockon a file opened by the trusted worker. - If a directory lock remains necessary, validate its ownership, type, and permissions before trusting it.
- Record the worker PID and verify process liveness before treating an existing lock as active.
- Install cleanup handlers before beginning work, for example with a shell
trapcovering normal exit and relevant signals. - Implement bounded stale-lock recovery and log rejected or recovered locks.
- Do not use lock existence alone as an authorization or trust decision.
- Store runtime locks in an owner-restricted directory such as
