T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:145- Finding
Mandatory Local Filesystem Access Without Runtime Authorization
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 145–158
Vulnerability Type: Unnecessary local file access and mandatory file creation
Risk Level: MediumComplete Code Snippet:
text ## PDF Output (automatically generated after every analysis) After completing the analysis, the report must be saved as a PDF file in the directory specified by the user: 1. Save location: D:\Downloads\ 2. File naming format: {stock name} ({stock code}) YYYY year MM month DD day analysis report.pdf Example: Shunwang Technology (300113) 2026-03-13 Analysis Report.pdf 3. HTML template: Refer to D:\Downloads\Shunwang_Technology_300113_Analysis_Report.html 4. Generation process: - First create an HTML file in the Downloads folderTechnical Analysis
The skill mandates access to a fixed local directory, reads a pre-existing local HTML template, and creates HTML and PDF files automatically after every stock analysis. These operations are not necessary to perform the skill's primary stock-analysis function.
The path is described as user-specified, but it is hardcoded and the workflow contains no requirement to obtain runtime consent, verify directory ownership, validate the generated filename, or prevent overwriting an existing file. Reading an external local template also places local content into the agent-controlled report-generation workflow without establishing that the file is trusted.
Attack Path
- A user requests an ordinary stock analysis.
- The skill automatically accesses the fixed
D:\Downloads\directory. - It attempts to read the specified local HTML template.
- It constructs output filenames from stock-related values and creates HTML and PDF files without requesting confirmation.
- If an output filename already exists, the workflow provides no protection against replacement or corruption.
Impact Assessment
The skill can cause unintended reads and writes within the ...[truncated 545 chars]
- Remediation
View remediation
Remediation Suggestions
- Make PDF export optional rather than mandatory.
- Obtain explicit user confirmation before reading or writing local files.
- Ask the user to select an output directory at runtime instead of using a fixed path.
- Use a trusted template bundled with the skill rather than reading an arbitrary external local template.
- Canonicalize and validate the destination path before writing.
- Sanitize stock names and codes before incorporating them into filenames.
- Reject path separators, traversal sequences, reserved device names, and unsupported characters.
- Check whether the destination already exists and require confirmation before overwriting it.
- Restrict filesystem access to a dedicated export directory with minimum required permissions.
