T09 · Insecure Skill Coding Practices
- Location
SKILL.md:308- Finding
Predictable Shared Temporary File Used for Generated Audio
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 308–312
Vulnerability Type: Predictable temporary file path and unsafe shared-file handling
Risk Level: MediumVulnerable code:
bash python3 ~/.workbuddy/skills/voice-coach/scripts/edge_tts_engine.py \ "${追问文本}" --voice yunjian --speed 0.95 -o /tmp/gejun_tts.mp3 afplay /tmp/gejun_tts.mp3Technical Analysis
The documented voice workflow always writes generated audio to the fixed, globally predictable path
/tmp/gejun_tts.mp3. Temporary directories such as/tmpare normally shared among users and processes. Reusing one predictable filename creates race conditions between concurrent Skill sessions and permits another local process to pre-create, replace, or monitor the file.Depending on how the external
edge_tts_engine.pyscript opens its output file, a local attacker may be able to place a symbolic link at that path before generation. If the script follows symbolic links and the invoking account can write to the link target, generated data could overwrite or truncate another file accessible to that account. The subsequentafplaycommand also reads the same path without verifying file ownership, type, permissions, or integrity.The file is not deleted after playback. Because its contents are derived from conversation text, leaving it behind may disclose user-provided information to other local processes or later sessions when system permissions permit access.
Attack Path
- A local attacker identifies that the Skill always uses
/tmp/gejun_tts.mp3. - Before or during voice generation, the attacker creates, replaces, or repeatedly swaps that path.
- Possible exploitation outcomes include:
- The attacker places controlled audio at the path after generation but before playback, causing attacker-selected content to be played.
- One concurrent session overwrites another session's audio, causing cross-session disclosur ...[truncated 1066 chars]
- A local attacker identifies that the Skill always uses
- Remediation
View remediation
Remediation Suggestions
Replace the fixed path with a private, uniquely generated temporary file and guarantee cleanup:
bash audio_file="$(mktemp "${TMPDIR:-/tmp}/gejun_tts.XXXXXX.mp3")" || exit 1 chmod 600 "$audio_file" trap 'rm -f -- "$audio_file"' EXIT HUP INT TERM python3 ~/.workbuddy/skills/voice-coach/scripts/edge_tts_engine.py \ "${prompt_text}" --voice yunjian --speed 0.95 -o "$audio_file" && afplay "$audio_file"Additional hardening measures:
- Prefer a per-user runtime directory with restrictive permissions over a globally shared temporary directory.
- Verify before playback that the output is a regular file owned by the current user and is not a symbolic link.
- Keep the path quoted in every command.
- Use
&&so playback occurs only if generation succeeds. - Delete the file immediately after playback and retain the cleanup trap for error and interruption paths.
- Ensure the external TTS engine creates output atomically and refuses to follow symbolic links where the platform supports that behavior.
- Use a distinct temporary file for every concurrent request or session.
