T09 · Insecure Skill Coding Practices
- Location
scripts/check.sh:20- Finding
Predictable State-File Write Can Follow Symbolic Links
- Content
View full analysis
100 then .[-100:] else . end)') echo "$new_state" > "$STATE_FILE" } ``` ### Technical Analysis The script writes state to a fixed, predictable path using ordinary shell redirection. It does not verify that the destination is a regular file, reject symbolic links, validate ownership of the workspace and memory directory, or perform the update through a securely created temporary file. Shell redirection follows symbolic links and truncates the resolved target before writing. A local actor who can create or replace `memory/context-guardian-state.json` could therefore make it point to another file writable by the account running the Skill. When `save_state` executes, the target file would be replaced with generated JSON state. The direct write is also non-atomic. Interruption or concurrent heartbeat invocations could leave a truncated or partially written state file. ### Attack Path 1. The attacker obtains write access ...[truncated 1216 chars]- Remediation
View remediation
&2 exit 1 fi tmp_file=$(mktemp "$STATE_DIR/.context-guardian-state.XXXXXX") chmod 600 "$tmp_file" printf '%s\n' "$new_state" > "$tmp_file" mv -f -- "$tmp_file" "$STATE_FILE" ``` The implementation should additionally verify directory ownership and use locking where multiple heartbeat invocations are possible. ]]>
