T09 · Insecure Skill Coding Practices
- Location
SKILL.md:114- Finding
Execution of Project-Controlled Makefile Targets
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:114-127;modules/template-rendering.md:166-173
Vulnerability Type: Execution of untrusted project-defined build commands
Risk Level: HighVulnerable Code
From
SKILL.md:bash # Check Makefile targets make help # List created files git statusThe subsequent workflow also advises executing additional project-defined targets:
bash # Install dependencies and hooks make dev-setup # Run tests to verify setup make test # See all available commands make helpFrom
modules/template-rendering.md:bash # Check Makefile works make help # Check git status git status # Verify directory structure tree -L 2Technical Analysis
The skill supports updating existing projects and instructs the agent or user to execute targets from the Makefile in the current working directory. Make targets are executable shell recipes, and target names such as
help,test, ordev-setupdo not provide any security guarantee.An attacker-controlled repository can define a malicious
helptarget or use Makefile features that execute commands while the file is parsed. Relevant mechanisms include target recipes, included Makefiles, shell expansion, and GNU Make functions such as$(shell ...). Consequently, even a target presented as validation can execute arbitrary commands with the privileges of the account running the skill.The workflow discusses conflict handling for existing files, but it does not require security inspection of the existing Makefile, its included files, or the exact recipes before execution. It also does not require isolation, network restrictions, or removal of credentials from the execution environment.
Attack Path
- An attacker prepares a repository containing a malicious
Makefile. - The victim opens or clones the repository and invokes the project initialization skill.
- The ex ...[truncated 1155 chars]
- An attacker prepares a repository containing a malicious
- Remediation
View remediation
Remediation Suggestions
- Do not automatically execute Makefile targets in existing or untrusted projects.
- Inspect the Makefile and every recursively included Makefile before execution.
- Display the exact target recipes and require explicit, informed user approval.
- Treat
make helpas executable code rather than as a read-only inspection command. - Prefer non-executing inspection where possible, such as displaying the generated file or validating expected text structurally.
- Distinguish newly generated, trusted files from pre-existing files and refuse to execute preserved project files by default.
- Run approved build targets inside an ephemeral sandbox or container with:
- No mounted credentials or sensitive home-directory content.
- Read-only access outside the project workspace.
- Network access disabled unless explicitly required.
- Minimal environment variables.
- Non-root privileges and resource limits.
- Record whether each executable file was generated during the current run, preserved from the repository, or modified during conflict resolution.
