Back to skill

Security audit

NBA Playoffs

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed NBA playoffs companion, but its optional flair image writer should be used with constrained output paths.

Install only if you want NBA playoff reminders and score posts in an existing configured messaging channel. Keep generated flair output inside a normal workspace/output folder, and review/remove NBA-related cron jobs if you stop using the skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
flair/generate-flair.py:95
Finding

Arbitrary File Overwrite Through Unrestricted Output Path

Content
View full analysis

Vulnerability Details

File Location: flair/generate-flair.py, lines 95–97 and 108
Vulnerability Type: Arbitrary file overwrite
Risk Level: Medium

Vulnerable Code:

python
if output_path:
    with open(output_path, "w", encoding="utf-8") as f:
        f.write(svg)
    return output_path

The path originates directly from a command-line argument:

python
output = sys.argv[3] if len(sys.argv) > 3 else None

Technical Analysis

The third command-line argument is accepted as output_path and passed unchanged to open() in truncating write mode. The script does not restrict output to a designated directory, reject absolute paths or traversal components, validate the resolved path, or protect against symbolic-link targets.

Consequently, a caller that controls this argument can direct the generated SVG content to any file writable by the process. The vulnerability does not independently elevate operating-system privileges; its reach is limited to the filesystem permissions of the user or Agent process running the script.

Attack Path

  1. An attacker influences the flair-generation output-path argument, directly or through an Agent request.
  2. The attacker supplies an absolute path, a traversal path such as ../../target, or a path resolving through a symbolic link.
  3. The CLI assigns the untrusted value to output.
  4. generate_flair() receives it as output_path.
  5. open(output_path, "w") creates or truncates the selected writable file.
  6. The script replaces the target's contents with generated SVG data.

Impact Assessment

Successful exploitation permits creation or overwrite of files available to the invoking process. This can corrupt workspace data, source files, local configuration, prediction records, or Agent state. If the process has access to security-sensitive configuration or executable startup files, overwriting those files may cause broader integrity ...[truncated 120 chars]

Remediation
View remediation

Remediation Suggestions

  • Write generated files only beneath a dedicated output directory.
  • Resolve both the trusted base directory and requested destination with pathlib.Path.resolve(), then verify that the destination remains beneath the base.
  • Reject absolute paths, .. traversal, unexpected path separators, and invalid filename characters.
  • Generate server-side filenames instead of accepting arbitrary destination paths where possible.
  • Reject symbolic-link destinations and inspect parent components to prevent symlink-based escapes.
  • Use exclusive creation mode ("x") when overwriting is unnecessary.
  • Run the generator with minimal filesystem permissions.
  • Return a clear validation error for destinations outside the authorized directory.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.