T09 · Insecure Skill Coding Practices
- Location
scripts/lib/common.sh:20- Finding
Unvalidated skill names enable path traversal, arbitrary file placement, and recursive deletion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Cocoloop is a coherent skill manager, but its installer and scanner handle remote packages, local files, and deletion with too little containment or confirmation.
Review before installing. Use this only if you are comfortable with a tool that can download skills, write them into agent-loaded directories, uninstall them, and upload local files for scanning. Avoid installing from untrusted URLs, avoid --force unless you have checked the destination paths, and do not run safescan on sensitive files unless you intend to upload them to the configured service.
scripts/lib/common.sh:20Unvalidated skill names enable path traversal, arbitrary file placement, and recursive deletion
scripts/lib/install.sh:243Untrusted archives are extracted without validating member paths or link targets
scripts/lib/install.sh:243Mutable remote skill content is installed without integrity or authenticity verification
scripts/lib/safescan.sh:40SafeScan transmits complete local files without explicit upload confirmation or endpoint disclosure
描述强调 CLI 的职责应很窄:只做网络 API 包装和已知安装流程包装,搜索判断、fallback 探索、复杂编排由 Agent 完成。但代码明显承担了这些被排除的职责。尤其是 search 命令会并发执行官方 API 搜索和本地搜索、输出结构化结果、判断是否无结果、判断 exact match、判断是否存在跨 agent 迁移候选,并在无结果时生成多个 fallback 站点 URL 和 next-step 建议。这已不是单纯 wrapper,而是实质性的决策与编排逻辑。除此之外,代码还实现了本地会话/安装状态管理、更新流程、点赞列表回退、本地/远程路径展示以及 safescan 安全扫描接口,能力范围显著大于声明。因此描述与实际行为存在明显不一致。
声明描述的是一个 Skill 管理器型 CLI,重点是 API wrapper 与安装流程 wrapper;但此代码块实际提供的是 SafeScan 功能集合,包含扫描报告查询、批量哈希存在性检查,以及将本地文件或目录发送到远程服务。这些能力明显超出了“Skill 管理器/安装流程封装”的直观范围,且其主要目的更接近安全扫描上传与查询,而不是 Skill 管理。虽然它确实属于某种 API wrapper,但访问和上传本地文件/目录到扫描端点是声明中未体现的实质能力,因此应判定为描述与行为不匹配。
声明强调 CLI 只负责网络 API wrapper 和已知安装流程 wrapper,复杂决策由 Agent 完成;但该代码片段的核心行为是本地卸载与清理:枚举多个技能安装目录,按 scope 筛选,并对存在的目录或符号链接执行递归删除,还会删除内部 store 并更新安装状态。这不是简单的网络 API 封装,也不属于安装流程 wrapper,而是具有破坏性的本地卸载能力。该能力和所访问的资源范围(项目目录、用户主目录下多种技能路径、内部存储)都未在声明中准确体现,因此存在明显描述与行为不一致。
Referenced artifact was not completely inspected
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。
Referenced artifact was not completely inspected
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。
Referenced artifact was not completely inspected
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。
Referenced artifact was not completely inspected
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。
Referenced artifact was not completely inspected
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。
The skill explicitly instructs installation into agent configuration and skill directories such as ~/.codex/config.toml, .agents/skills, and other platform-specific paths. In context, this is more dangerous because the skill is an installer/manager: modifying agent config locations can persist behavior, alter what code the agent loads, and create a persistence foothold across future sessions or projects.
| 平台 | 项目级目录 | 用户级目录 | 兼容目录 | 配置示范 |
| --- | --- | --- | --- | --- |
| OpenCode | `.opencode/skills/<skill-name>/` | `~/.config/opencode/skills/<skill-name>/` | `.claude/skills/<skill-name>/`、`.agents/skills/<skill-name>/` 也可被 OpenCode 发现 | `opencode.json` / `~/.config/opencode/opencode.json` |
| Codex | `.agents/skills/<skill-name>/` | `$HOME/.agents/skills/<skill-name>/` | `$HOME/.codex/skills/<skill-name>/` | `~/.codex/config.toml` |
| Claude Code | `.claude/skills/<skill-name>/` | `~/.claude/skills/<skill-name>/` | 无必需兼容目录 | `~/.claude/settings.json` / `.claude/settings.json` |
| OpenClaw | `skills/<skill-name>/` 或 `.agents/skills/<skill-name>/` | `~/.agents/skills/<skill-name>/` 或 `~/.openclaw/skills/<skill-name>/` | `~/.openclaw/skills/<skill-name>/` | `~/.openclaw/openclaw.json` |
| Molili | 无独立项目级目录,直接使用用户级 active skills 目录 | macOS/Linux: `~/.molili/workspaces/default/active_skills/<skill-name>/`;Windows: `\\.molili\\workspaces\\default\\active_skills\\<skill-name>\\` | 无额外兼容目录 | 以 `active_skills` 目录为准 |
Referencing and potentially modifying files like ~/.claude/settings.json exposes sensitive agent configuration state and enables persistence or behavioral manipulation. Because this skill's purpose is to install and publish skills into active agent ecosystems, access to these config paths materially increases the blast radius if the workflow is misused or if an untrusted skill is installed.
| --- | --- | --- | --- | --- |
| OpenCode | `.opencode/skills/<skill-name>/` | `~/.config/opencode/skills/<skill-name>/` | `.claude/skills/<skill-name>/`、`.agents/skills/<skill-name>/` 也可被 OpenCode 发现 | `opencode.json` / `~/.config/opencode/opencode.json` |
| Codex | `.agents/skills/<skill-name>/` | `$HOME/.agents/skills/<skill-name>/` | `$HOME/.codex/skills/<skill-name>/` | `~/.codex/config.toml` |
| Claude Code | `.claude/skills/<skill-name>/` | `~/.claude/skills/<skill-name>/` | 无必需兼容目录 | `~/.claude/settings.json` / `.claude/settings.json` |
| OpenClaw | `skills/<skill-name>/` 或 `.agents/skills/<skill-name>/` | `~/.agents/skills/<skill-name>/` 或 `~/.openclaw/skills/<skill-name>/` | `~/.openclaw/skills/<skill-name>/` | `~/.openclaw/openclaw.json` |
| Molili | 无独立项目级目录,直接使用用户级 active skills 目录 | macOS/Linux: `~/.molili/workspaces/default/active_skills/<skill-name>/`;Windows: `\\.molili\\workspaces\\default\\active_skills\\<skill-name>\\` | 无额外兼容目录 | 以 `active_skills` 目录为准 |
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令
## 检查维度
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令
## 检查维度
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令
## 检查维度
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令
## 检查维度
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令
## 检查维度
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令
## 检查维度
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
### A 级
- 代码安全规范
- 依赖版本锁定
- 无动态代码加载
- 允许 T3 来源
### B 级
- 无 C/D 级问题
- 存在改进空间
### C 级
- 存在潜在安全漏洞
- 硬编码敏感信息
### D 级(一票否决)
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令
## 检查维度
### 1. 代码安全性检查
**D级触发项**:
- 使用 `eval()` 执行不可信网络代码
- 使用 `exec()`、`system()` 执行未过滤的用户输入
- 存在 SQL 注入、命令注入、XSS 等明显漏洞
- 存在已知的严重 CVE 漏洞
**C级触发项**:
- 存在潜在的安全漏洞(路径遍历、不安全的反序列化)
- 硬编码敏感信息(密码、API Key、Token)
### 2. 数据隐私性检查
**D级触发项**:
- 未经用户确认上传本地文件到远程(T3 来源)
- 静默收集密码、密钥�
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
### 3. 执行安全性检查
**D级触发项**:
- 执行 `rm -rf /` 或类似系统破坏性命令
- 无确认直接执行系统级危险操作
- 修改系统关键配置且无备份机制
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
### 3. 执行安全性检查
**D级触发项**:
- 执行 `rm -rf /` 或类似系统破坏性命令
- 无确认直接执行系统级危险操作
- 修改系统关键配置且无备份机制
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
### 3. 执行安全性检查
**D级触发项**:
- 执行 `rm -rf /` 或类似系统破坏性命令
- 无确认直接执行系统级危险操作
- 修改系统关键配置且无备份机制
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
git status --short git add <需要发布的文件> git commit -m "" git push origin main
如果有本地维护手册、测试文件或临时产物,确认它们已经被 `.gitignore` 排除。
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
git status --short git add <需要发布的文件> git commit -m "" git push origin main
如果有本地维护手册、测试文件或临时产物,确认它们已经被 `.gitignore` 排除。
The guide allows T3-source pre-installation checks to be bypassed with a '--skip-check' parameter. Because T3 is explicitly the least trusted source tier, documenting a straightforward bypass of recommended safety review weakens a key control and can lead users to install unreviewed, potentially malicious skills.
1. **安装前检查**(推荐)
- 用户明确请求:"检查 xxx 安全"
- 来源为 T3 且用户未使用 --skip-check 参数
2. **安装后检查**
- 安装完成后询问用户是否需要检查
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| --------------- | -------------------- | ------------------------------ |
| `eval\s*\(` | 使用 eval 执行代码 | `eval(userInput)` |
| `exec\s*\(` | 使用 exec 执行命令 | `exec(userCommand)` |
| `system\s*\(` | 使用 system 执行命令 | `system("rm -rf /")` |
| `child_process` | 引入 child_process | `require('child_process')` |
| `spawn\s*\(` | 使用 spawn 执行命令 | `spawn('sh', ['-c', cmd])` |
| `rm\s+-rf\s+/` | 系统破坏性命令 | `rm -rf /` |
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
| `child_process` | 引入 child_process | `require('child_process')` |
| `spawn\s*\(` | 使用 spawn 执行命令 | `spawn('sh', ['-c', cmd])` |
| `rm\s+-rf\s+/` | 系统破坏性命令 | `rm -rf /` |
| `curl.*\|.*sh` | 管道执行远程脚本 | `curl http://x.com/s.sh \| sh` |
| `fetch.*eval` | 下载并执行代码 | `fetch(url).then(r=>eval(r))` |
**C级触发项:**
No suspicious patterns detected.