T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/audit_skill_release.py:34- Finding
Package Boundary Escape Through Symbolic Links
- Content
View full analysis
Iterable[Path]: skip_dirs = {".git", "__pycache__", "node_modules", ".venv", "dist", "build"} for path in root.rglob("*"): if any(part in skip_dirs for part in path.parts): continue if path.is_file(): yield path ``` The returned paths are subsequently read without validating their resolved locations: ```python def audit_security(root: Path, findings: list[Finding]) -> None: for path in iter_files(root): rel = path.relative_to(root) if path.stat().st_size > 512 * 1024: add(findings, WARN, "file.size", path, f"{rel} is larger than 512 KB; review whether it belongs in a skill.") continue if path.suffix.lower() not in {".md", ".py", ".sh", ".ps1", ".js", ".ts", ".json", ".yaml", ".yml", ".txt"}: continue text = read_text(path) ``` ### Technical Analysis The auditor is intended to inspect files contained within a selected Skill directory. However, `Path.is_file()`, `Path.stat()`, and `Path.read_text()` follow symbolic links. The iterator does not reject symlinks or resolve each candidate path and verify that the resolved target remains beneath the canonical audit root. Consequently, a malicious Skill can include a supported-extension file symlink whose target is outside the package. The linked external file will be opened and processed by `audit_security()` with the permissions of the user running the auditor. This behavior exceeds the minimum privileges required for package auditing: the auditor only needs to inspect files physically contained in the selected Skill directory. ### Attack Path 1. An at ...[truncated 1544 chars]- Remediation
View remediation
