T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:75- Finding
Unrestricted Output Path Allows Arbitrary File Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears intended to generate clinical form JSON, but its script can write to any user-supplied file path the running account can access.
Review before installing or running. Use only explicit workspace-relative output paths, avoid passing paths from untrusted input, and do not run it in directories where overwriting a writable file would matter until output path validation or overwrite protection is added.
scripts/main.py:75Unrestricted Output Path Allows Arbitrary File Overwrite
The skill metadata describes capabilities consistent with writing files, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens enforcement and review boundaries, because an agent or runtime may permit broader file operations than users expect, increasing the chance of unintended or unsafe workspace modification.
The skill states that local scripts may be executed and output files may be written, but it does not clearly warn users about the operational and safety consequences of running code or modifying local files. This can lead to unsafe use, especially in agentic environments where users may assume the skill is metadata-only and not realize it can change filesystem state.
No suspicious patterns detected.