T09 · Insecure Skill Coding Practices
- Location
scripts/file_finder.sh:38- Finding
Arbitrary Python Code Execution Through the large Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This file-finder skill is a real filesystem utility, but it contains unsafe argument handling that can execute injected Python code and it under-describes its broader analysis features.
Do not install this version until the embedded Python blocks are changed to pass arguments safely and the manifest is updated to disclose the full filesystem analysis behavior and intended directory scope. There is no evidence of a backdoor or persistence, but a crafted path argument could run code with the same access as the agent or user invoking the skill.
scripts/file_finder.sh:38Arbitrary Python Code Execution Through the large Command
scripts/file_finder.sh:81Arbitrary Python Code Execution Through the dup Command
scripts/file_finder.sh:135Arbitrary Python Code Execution Through the summary Command
The manifest presents the skill as a simple fd-style file finder, but the detected behavior includes substantially broader filesystem inspection and analysis capabilities such as hashing, size analysis, recency reporting, and tree/statistical summaries. This mismatch can mislead users and policy systems about what the skill actually does, increasing the risk of unintended data exposure and overbroad file enumeration.
The skill declares runtime and exposes filesystem-oriented behavior, but it does not define any explicit tool scope such as permissions or allowed-tools. In an agent environment, missing scope boundaries can lead to broader-than-intended file read access and makes it harder to enforce least privilege.
Generic triggers like help, run, info, and status are overly broad and are likely to collide with normal agent workflows or other skills. That can cause accidental invocation of this skill in unintended contexts, which is especially risky for a filesystem-oriented tool that may enumerate or inspect local files.
The usage text says 'Run any command,' which signals unconstrained command handling rather than a fixed, narrowly defined interface. In practice, ambiguous command acceptance can expand the reachable behavior surface and undermine enforcement of safe, expected operations.
## Usage
Run any command: `file-finder <command> [args]`
---
> **Disclaimer**: This skill is an independent, original implementation. It is not affiliated with, endorsed by, or derived from the referenced open-source project. No code was copied. The reference is for context only.
The manifest presents this skill as a fast alternative to 'find', implying file-location functionality. However, the help text and implemented commands add broader analysis capabilities such as duplicate detection, large-file analysis, recency reporting, directory summaries, and tree views, which materially expand the behavior beyond simple file finding.
The top-level comment describes the script as 'File Finder — fast file search', aligning with a narrow search utility. Immediately below, the user-facing help expands the intent to 'fast file search & analysis' and exposes analysis-oriented commands, creating a direct documentation-level divergence about the tool's intended scope.
No suspicious patterns detected.