T09 · Insecure Skill Coding Practices
- Location
SKILL.md:36- Finding
Predictable Shared Temporary File Enables Symlink Attacks and Review Data Exposure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 36
Vulnerability Type: Predictable and insecure temporary file usage
Risk Level: MediumVulnerable Code:
bash git diff BASE_SHA HEAD > /tmp/review-diff.patchTechnical Analysis
The documented workflow writes potentially sensitive source-code changes to the fixed, globally predictable path
/tmp/review-diff.patch. Shell output redirection follows an existing symbolic link and truncates its target before writing. A local attacker who can create that path before the command runs could therefore redirect the write to another file writable by the victim account.The fixed path also creates concurrency and confidentiality risks. Multiple review processes can overwrite or consume one another's patch data. Depending on the invoking process's
umaskand the resulting file permissions, proprietary source changes may be readable by other local users.Attack Path
- A local attacker predicts that the documented review workflow will use
/tmp/review-diff.patch. - Before the workflow runs, the attacker creates that path as a symbolic link to a file writable by the victim account, or places a competing patch file at that location.
- The victim executes:
bash git diff BASE_SHA HEAD > /tmp/review-diff.patch - The shell follows the symbolic link and truncates or overwrites its target, or overwrites the attacker's competing file.
- Alternatively, the attacker reads or modifies the generated patch if local permissions allow it.
- The review subagent may subsequently receive attacker-modified review input, while legitimate source changes may be exposed or lost.
Exploitation requires local access to the shared temporary directory and favorable timing or prior placement of the predictable path.
Impact Assessment
The vulnerability does not independently grant additional operating-system privileges. Its impact is limit ...[truncated 618 chars]
- A local attacker predicts that the documented review workflow will use
- Remediation
View remediation
Remediation Suggestions
Replace the predictable shared path with a securely created, private temporary directory or file. Apply restrictive permissions before creating the patch and guarantee cleanup:
bash umask 077 review_dir="$(mktemp -d)" || exit 1 trap 'rm -rf -- "$review_dir"' EXIT review_patch="$review_dir/review-diff.patch" git diff BASE_SHA HEAD > "$review_patch"Additional hardening measures:
- Do not use a fixed filename directly under
/tmp. - Keep every invocation's artifacts in a unique temporary directory.
- Quote all generated path variables.
- Ensure temporary artifacts are removed on normal exit and interruption.
- Avoid running the review workflow with elevated privileges.
- Pass the diff directly to the review subagent when practical, avoiding filesystem storage entirely.
- If the patch must persist, store it in a project-controlled directory with explicit owner-only permissions and validate ownership before use.
- Do not use a fixed filename directly under
