T09 · Insecure Skill Coding Practices
- Location
scripts/feishu-fetch.sh:157- Finding
Path Traversal Through an Untrusted Attachment Filename Allows Arbitrary File Overwrite
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi ``` 6. **Validate explicit `--output` paths separately.** If arbitrary output paths are required functionality, clearly treat them as trusted caller input and still refuse unintended overwrites unless an explicit option such as `--force` is supplied. 7. **Add regression tests** covering filenames such as: ```text ../../home/user/.bashrc ../target /path/to/file ..\target . .. ``` Tests should verify that the final canonical path remains inside the approved download directory and that existing files are not replace ...[truncated 17 chars]
