T09 · Insecure Skill Coding Practices
- Location
scripts/scaffold.sh:22- Finding
Theme Identifier Path Traversal Allows Files Outside the Theme Directory to Be Copied
- Content
View full analysis
/dev/null; exit 0 ;; --*) echo "Unknown option: $arg" >&2; exit 1 ;; *) TARGET="$arg" ;; esac done THEME_TOKENS="$SKILL_DIR/themes/$THEME/tokens.css" if [ ! -f "$THEME_TOKENS" ]; then echo "Theme not found: $THEME (looked for $THEME_TOKENS)" >&2 echo "Available themes:" >&2 ls "$SKILL_DIR/themes" 2>/dev/null >&2 || true exit 1 fi ``` The resulting path is later copied into the generated project: ```bash cp "$THEME_TOKENS" "$TARGET/src/theme/tokens.css" ``` ### Technical Analysis The value supplied through `--theme` is interpolated directly into a filesystem path. The script does not restrict the value to a valid theme identifier, reject path separators or `..` components, or verify the canonical source path remains under `$SKILL_DIR/themes`. Shell quoting prevents command injection, but it does not prevent filesystem path traversal. A value containing traversal components can resolve outside the intended theme directory. The regular-file check only establishes that the resolved path exists; it does not establish that it belongs to an authorized theme. Exploitation is constrained by the hardcoded `tokens.css` suffix. The attacker must identify or arrange a reachable path ending in `tokens.css`. Nevertheless, if such a path exists, the script can copy that file into the generated presentation. ### Attack Path 1. An attacker or untrusted automation controls the arguments passed to `scaffold.sh`. 2. The attacker identifies a readable file outside the theme directory whose path ends in `tokens.css`. 3. The attacker supplies a traversal value, for ex ...[truncated 1094 chars]- Remediation
View remediation
&2 exit 1 fi ``` 2. Prefer selecting themes from an enumerated list of directories directly under `$SKILL_DIR/themes`. 3. Canonicalize the theme root and requested file, then verify containment: ```bash THEMES_ROOT="$(realpath "$SKILL_DIR/themes")" THEME_TOKENS="$(realpath "$SKILL_DIR/themes/$THEME/tokens.css")" case "$THEME_TOKENS" in "$THEMES_ROOT"/*) ;; *) echo "Theme path escapes the authorized theme directory." >&2 exit 1 ;; esac ``` 4. Retain the regular-file check after canonicalization. 5. Add regression tests covering `../`, absolute paths, repeated separators, symbolic links, and valid theme identifiers. ]]>
