T09 · Insecure Skill Coding Practices
- Location
generate_contract.py:969- Finding
Unconditional Overwrite of User-Selected Output Files
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a local contract document generator with expected file-writing behavior, but users should choose output paths carefully because generated files can replace existing files.
Install only if you are comfortable with a local generator that saves contract details, including contact information and terms, into PDF and Markdown files. Use a dedicated output folder, avoid pointing outputs at existing important files, and review generated contracts with qualified counsel before using them for a real engagement.
generate_contract.py:969Unconditional Overwrite of User-Selected Output Files
Referenced artifact was not completely inspected
| `generate_contract.py` | Contract, Markdown, and envelope generator. |
Referenced artifact was not completely inspected
| `generate_contract.py` | Contract, Markdown, and envelope generator. |
The skill advertises document generation that updates configs and produces output files, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agentic environment, undeclared file-write capability weakens least-privilege controls and can let the skill modify files beyond what a reviewer or orchestrator expects.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| Unknown values | Keep unknown provider, client, agreement, delivery, and agentic-development values as `TBD`. |
| Artifact status | Treat generated PDFs and Markdown as draft artifacts until the user confirms the terms and facts. |
| Skill boundary | Keep contract generation separate from proposals, invoices, delivery records, security signoff, customer success notes, email copy, and delivery packaging decisions. |
| Existing files | Do not overwrite user-specific config or generated output without checking whether it contains client-specific facts that should be preserved. |
## Configuration Toggles
This code writes a filled Markdown file to a user-specified path, and the rendered content is likely to include names, addresses, emails, and contract terms from the config. Although the script prints the output path afterward, there is no earlier user-facing warning, prompt, or comment near the write explaining that a plaintext copy of the contract will be saved alongside the PDF.
When enabled, the script creates a separate addressed envelope PDF using provider and client address fields, which are personal or business contact details. The operation is printed only after creation and lacks a clear prior disclosure or inline warning that another file with address data will be produced.
No suspicious patterns detected.