T09 · Insecure Skill Coding Practices
- Location
scripts/run-unity-render.sh:22- Finding
Arbitrary File Deletion and Overwrite Through Unvalidated Output Paths
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real Aavegotchi renderer, but direct render requests can delete or overwrite arbitrary writable files, so it should be reviewed before installation.
Install only in an isolated, low-privilege workspace and avoid feeding untrusted request JSON directly to the hosted or Unity runners. Prefer the main wrapper until output paths are generated internally or restricted to a dedicated render directory, and pin the Unity SDK dependency to a reviewed immutable revision.
scripts/run-unity-render.sh:22Arbitrary File Deletion and Overwrite Through Unvalidated Output Paths
unity/GotchiCustomRenderer/Packages/manifest.json:5Unity SDK Dependency Tracks a Mutable Remote Branch
The declared description says this skill renders custom Aavegotchi 3D images from arbitrary trait and wearable combinations for user outfit/appearance preview requests. The supplied code does not do any rendering, image generation, or preview creation. Instead, it reads JSON from a file or stdin, applies default values, requires specific fields (collateral, eye_shape, eye_color), validates integer fields for haunt_id, skin_id, and wearable slots, rejects unknown wearable slots, and prints a normalized JSON payload. This is a config validator/normalizer, which is materially different from the declared primary purpose of rendering custom 3D images.
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
Referenced artifact was not completely inspected
- main wrapper: `scripts/render-custom-gotchi.sh`
The skill advertises execution paths that read local files and access hosted resources, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, missing scope metadata can cause over-broad tool access, make policy enforcement ambiguous, and increase the risk of unintended file exposure or network use if the skill is routed automatically.
The default prompt strongly instructs the agent to invoke this skill whenever a user describes a custom Aavegotchi look in plain language, with broad examples and little gating. That can cause over-triggering on ambiguous descriptive requests, leading the agent to route users into this skill when another tool or a clarification step would be more appropriate.
The script deletes a path taken from untrusted input via MANIFEST_JSON="$(jq -r '.output.manifest_json' "$INPUT_JSON")" and then rm -f "$MANIFEST_JSON" ... without validating that the path is within an expected output directory. An attacker who can influence the input JSON can cause deletion of arbitrary files accessible to the current user, and the skill context makes this more dangerous because the renderer is explicitly designed to consume arbitrary user-supplied request files.
The code creates parent directories and writes PNG and manifest files to paths taken directly from untrusted JSON input, with no restriction to a safe output directory. In a CLI/editor context, an attacker who can control the request file can overwrite arbitrary files writable by the current user or CI agent, which is especially risky because this skill accepts synthetic requests rather than fixed on-chain assets.
The dependency uses a caret range (^7.0.0), which allows automatic installation of newer compatible releases rather than a single fixed version. This increases supply-chain risk because builds are not fully reproducible and a compromised or faulty upstream release could be pulled in without an explicit review. In this skill, the risk is somewhat limited because the file only declares a common image-processing library and does not itself contain suspicious install hooks or scripts.
"description": "Custom Aavegotchi 3D renderer with hosted official-style output and Unity fallback.",
"type": "module",
"dependencies": {
"pngjs": "^7.0.0"
}
}
This markdown file documents that the skill writes PNG and JSON artifacts to a local temporary directory, which affects the user's filesystem. Under the markdown-specific warning criterion, the description should disclose this behavior more explicitly as a user-impacting side effect rather than only mentioning it as an implementation detail.
This script writes image output to the user-specified path, which can overwrite or create files, but the code provides no confirmation prompt, warning message, or explanatory comment about this side effect. For a code file, file-writing behavior is safety-relevant and should include some disclosure unless the warning is provided elsewhere.
The command accepts --input and reads the referenced JSON file directly from disk, which is a filesystem access operation driven by external input. The existing trace log is not a meaningful user disclosure, and there is no comment or documentation in this file warning that the skill consumes local file contents from the provided path.
During rendering, the skill scans project assets and reads material files from disk, including direct File.ReadAllLines on asset paths to hydrate fallback materials. These filesystem reads are not surfaced to the user through a visible warning, confirmation, or explanatory documentation in the file.
No suspicious patterns detected.