Back to skill

Security audit

Clean Filenames

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local filename-cleaning tool, but users should understand it renames files and recursive mode can affect many files.

Install only if you are comfortable with a tool that renames existing files. Use it first on a small test folder, be careful with recursive mode, and keep backups for directories where filename changes could break links, scripts, media libraries, or workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
tool.py:23
Finding

Non-Atomic Destination Check Can Cause Existing Files to Be Overwritten

Content
View full analysis

Vulnerability Details

File Location: tool.py, lines 23–34
Vulnerability Type: Time-of-check to time-of-use race condition
Risk Level: Medium

Vulnerable Code:

python
if new_path == path:
    return False  # No change needed

if os.path.exists(new_path):
    print(f"Conflict: {new_path} already exists. Skipping '{os.path.basename(path)}'.", file=sys.stderr)
    return False

try:
    os.rename(path, new_path)
    print(f"Renamed: '{os.path.basename(path)}' → '{new_name}'")
    return True
except OSError as e:
    print(f"Error renaming '{os.path.basename(path)}': {e}", file=sys.stderr)
    return False

Technical Analysis

The destination existence check and the subsequent rename are separate filesystem operations. The destination can therefore change after os.path.exists(new_path) returns False but before os.rename(path, new_path) executes.

On platforms where os.rename() replaces an existing destination, a file created during this interval may be overwritten. Consequently, the implementation does not reliably satisfy its stated guarantee of avoiding overwrites. Exploitation requires the attacker to have write access to the directory being processed and sufficient ability to win or repeatedly attempt the race.

Attack Path

  1. A victim runs the filename-cleaning tool against a directory writable by an attacker.
  2. The tool derives a sanitized destination name from an existing filename.
  3. The tool checks os.path.exists(new_path) and observes that the destination does not exist.
  4. Before os.rename() executes, the attacker creates a file at new_path.
  5. On a platform with replacement semantics, os.rename() replaces the attacker's newly created destination with the source file.
  6. The destination's prior contents are lost.

Impact Assessment

The issue can cause local file replacement and data loss within directories where both the victim process and ...[truncated 321 chars]

Remediation
View remediation

Remediation Suggestions

Use an atomic no-replace operation rather than checking for existence before renaming. On Linux, an implementation may use renameat2() with RENAME_NOREPLACE; equivalent platform-specific primitives should be used elsewhere.

If portability is required, implement a carefully reviewed strategy that atomically reserves the destination and handles rollback without exposing another check-to-use interval. Treat symbolic links and all unexpected filesystem object types as conflicts. Clearly document any platform on which overwrite prevention cannot be guaranteed, and add concurrent filesystem tests that attempt to create the destination during the rename operation.

T09 · Insecure Skill Coding Practices

Note
Location
tool.py:23
Finding

Unescaped Filenames Can Inject Terminal Control Sequences into Console Output

Content
View full analysis

Vulnerability Details

File Location: tool.py, lines 23–34
Vulnerability Type: Terminal escape-sequence injection
Risk Level: Low

Vulnerable Code:

python
if new_path == path:
    return False  # No change needed

if os.path.exists(new_path):
    print(f"Conflict: {new_path} already exists. Skipping '{os.path.basename(path)}'.", file=sys.stderr)
    return False

try:
    os.rename(path, new_path)
    print(f"Renamed: '{os.path.basename(path)}' → '{new_name}'")
    return True
except OSError as e:
    print(f"Error renaming '{os.path.basename(path)}': {e}", file=sys.stderr)
    return False

Additional affected output statements occur at lines 87 and 92:

python
print(f"No change needed: '{base}'")
python
print(f"Error: Path '{args.path}' does not exist.", file=sys.stderr)

Technical Analysis

Attacker-controlled filenames and paths are interpolated directly into terminal output without escaping control characters. Although clean_name() removes control characters from a generated destination name, the original basename, input path, and potentially exception-derived text are still emitted in raw form.

Unix-like filesystems permit filenames containing escape bytes and other control characters apart from NUL and the path separator. When output is displayed by a compatible interactive terminal, those characters may modify terminal presentation, conceal or rewrite messages, create misleading output, or activate terminal-specific escape-sequence behavior.

This issue is an output-injection flaw rather than shell command injection: the code does not invoke a shell, and the filename is not executed as a command.

Attack Path

  1. An attacker creates a file whose name contains ANSI escape sequences or other terminal control characters.
  2. The victim runs the tool on that file or its containing directory.
  3. A rename, conflict, no-change, or error branch pri ...[truncated 622 chars]
Remediation
View remediation

Remediation Suggestions

Escape all untrusted filenames, paths, and exception-derived strings before writing them to an interactive terminal. Use a consistent safe-rendering helper based on ascii(), repr(), or explicit encoding of control characters. For example:

python
def display_path(value):
    return ascii(os.fspath(value))

Apply the helper to every output branch, including successful renames, conflicts, errors, unchanged filenames, and nonexistent input paths. If machine-readable output is supported later, serialize values with a structured format such as JSON rather than embedding raw filenames in prose. Add tests using filenames containing \x1b, carriage returns, newlines, tabs, and other control bytes.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises filename cleaning and shows recursive directory usage, but it does not clearly warn users that it will rename existing files, potentially across many files and subdirectories. This can cause unintended data-management impact, break references or workflows that depend on original filenames, and create user harm if the operation is run in the wrong path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.