T09 · Insecure Skill Coding Practices
- Location
scripts/daily_tracker.py:20- Finding
Arbitrary JSON File Access Through Date Path Traversal
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This baby-care record skill has a coherent purpose, but its local file handling can read, overwrite, or delete JSON files outside its intended data folder and it includes under-disclosed permanent deletion.
Install only after reviewing the local-file risks. The skill is not showing network exfiltration or hidden persistence, but it should validate dates, confine all file access to its data directory, disclose deletion, and require explicit confirmation before saving or deleting sensitive baby-care records.
scripts/daily_tracker.py:20Arbitrary JSON File Access Through Date Path Traversal
The declared behavior does not match the actual capability surface: the skill promises image/voice-style intake that is not implemented, while static analysis indicates an undeclared delete capability. Undisclosed destructive functionality is particularly risky because users and reviewers cannot accurately assess what actions the skill may take on stored baby-care records.
The skill invokes a Python script that reads and writes local JSON files, but it declares no explicit tool scope or permissions. This weakens least-privilege controls and makes the skill’s file access harder to review or constrain, increasing the chance of unintended filesystem access if the implementation changes or is abused.
该技能在描述中列出“帮我看看这张表(图片)”“宝宝日记”“每日情况汇总”等触发内容,其中部分短语缺少足够的领域约束,可能在一般聊天或图片理解场景中也会出现。说明中也未提供排除条件或负例来界定何时应触发、何时不应触发,因此存在非预期调用风险。
The oral-input flow instructs the agent to save user-provided health-related data immediately without a pre-save notice or confirmation step. Because the data concerns a baby’s daily care and is persisted to disk, accidental, misheard, or injected information could be stored permanently and later relied upon as if accurate.
“所有交互使用中文”属于明确的语言限定,但文档中未说明这是用户可选项,也未解释该技能为何必须仅使用中文。按照语言/locale 政策要求,未经用户选择即强制特定语言可能构成自然语言策略违规。
This markdown file presents all headings, field descriptions, and usage guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.
The module docstring is entirely in Chinese and presents the tool as a Chinese-only baby care record utility. Under the policy rules, forcing a specific language without user opt-in is a natural-language locale violation when no alternative language choice or justification is provided.
The manifest describes this skill as supporting baby daily data entry, lookup, and summary generation, with data stored as JSON files. The code also implements a delete command that removes daily records from disk, which is a materially different destructive behavior not suggested by the manifest description or trigger phrases.
The delete operation permanently removes stored baby-care records immediately when invoked, with no confirmation, undo, or soft-delete behavior. In an agent context, an accidental, ambiguous, or manipulated command could cause irreversible loss of sensitive caregiving history, affecting record integrity and availability.
The save path persists sensitive baby health and care information to local JSON files without any disclosure, consent flow, retention notice, or protection mechanism. In skill/agent usage, users may assume ephemeral processing, so silent persistence increases privacy risk if the host environment is shared, backed up, or otherwise accessible.
No suspicious patterns detected.