T09 · Insecure Skill Coding Practices
- Location
scripts/pl-init.sh:38- Finding
Unvalidated Plan Name Permits Filesystem Path Manipulation
- Content
View full analysis
"$file_path" <- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill creates local planning documents as advertised, with no network, credential, persistence, or hidden behavior, though its filename handling should be tightened.
Install only if you want a Chinese-language planning initializer that creates Markdown files in your workspace. Avoid using slashes, dots, shell metacharacters, or unusual characters in plan names until the script enforces a strict safe-name pattern.
scripts/pl-init.sh:38Unvalidated Plan Name Permits Filesystem Path Manipulation
scripts/pl-init.sh:46Predictable Check-Then-Write Sequence Allows a Symbolic-Link Race
该 markdown 文件将技能描述为“启动一个新的规划流程,创建新的规划文件”以及“启动一个新的规划”,并仅要求用户请求“包含变更名称或对想要构建内容的描述”。这些表述较宽泛,容易与日常的泛化“做个规划/想构建什么”类请求重叠,文档中也没有提供明确触发短语、适用范围限制或不应触发的负例。
文档要求“提炼出简洁的中文规划主题”,属于对输出语言的硬性限定。文件中未见用户可选择语言/locale 的机制,也未说明该技能为何必须仅使用中文,因此构成语言/locale 政策风险。
技能要求调用本地 shell 脚本并立即向新建文件写入用户衍生内容,但文档没有要求对规划名称做严格校验、转义或向用户提示文件系统副作用。若脚本参数处理不安全,用户提供的名称可能触发命令注入、路径穿越或意外文件创建;即使脚本本身安全,缺少显式风险提示也会增加误操作和静默写盘风险。
The script description, help text, and user-visible messages are written in Chinese only, including usage guidance and success/error output. This imposes a specific language on users without any opt-in, fallback, or documented justification for a locale-specific audience.
No suspicious patterns detected.