T09 · Insecure Skill Coding Practices
- Location
SKILL.md:76- Finding
Predictable Temporary File Allows Symlink-Based File Overwrite and Race-Condition Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 76–103
Vulnerability Type: Unsafe predictable temporary file
Risk Level: MediumVulnerable Code
bash cat > /tmp/ta_radar_run.py << 'PYEOF' <PASTE COMPLETE PYTHON SCRIPT HERE> PYEOFbash TA_SYMBOL="<SYMBOL>" TA_INTERVAL="<INTERVAL>" python3 /tmp/ta_radar_run.pybash rm -f /tmp/ta_radar_run.pyTechnical Analysis
The workflow writes and executes Python code at the fixed, globally predictable path
/tmp/ta_radar_run.py. Ordinary shell redirection follows symbolic links and does not create the file exclusively. The instructions also do not verify file ownership, type, or permissions before writing and executing it.On a shared system, another local user can prepare this path as a symbolic link. When the workflow performs the redirection, it may overwrite the symbolic link's target with the Agent's privileges. There is also a time-of-check/time-of-use race between writing and executing the file: an attacker able to manipulate the shared temporary directory could replace the path after the write but before Python opens it.
The cleanup command does not prevent either issue. It runs only after execution and removes the pathname rather than securely controlling the temporary file throughout its lifecycle.
Attack Path
Symlink overwrite scenario:
- A local attacker predicts that the Skill will use
/tmp/ta_radar_run.py. - Before invocation, the attacker creates that path as a symbolic link to a file writable by the Agent.
- The Agent follows the Skill instructions and writes the embedded script through shell redirection.
- The operating system follows the symbolic link, overwriting the target file with the Agent's privileges.
- The final
rm -fremoves the temporary pathname but cannot undo corruption of the target.
Race-condition execution scenario:
- The Agent writes ...[truncated 1085 chars]
- A local attacker predicts that the Skill will use
- Remediation
View remediation
Remediation Suggestions
Create a private, uniquely named temporary directory and place the script inside it. Apply restrictive permissions before writing and register cleanup immediately:
bash tmpdir="$(mktemp -d)" || exit 1 trap 'rm -rf -- "$tmpdir"' EXIT umask 077 script="$tmpdir/ta_radar_run.py" cat > "$script" <<'PYEOF' # Complete embedded Python script PYEOF TA_SYMBOL="$SYMBOL" TA_INTERVAL="$INTERVAL" python3 "$script"Additional hardening should include:
- Do not reuse a fixed pathname in a shared directory.
- Ensure the temporary directory is owned by the current account and has mode
0700. - Keep the script inaccessible to other users with
umask 077. - Avoid separating creation from execution through an attacker-manipulable path.
- Run the Skill as an unprivileged account with access limited to resources required for market analysis.
- Use an exit trap so cleanup occurs on success, failure, or interruption.
- Where supported, execute the embedded program directly from a securely opened file descriptor or avoid materializing it as a file.
