T09 · Insecure Skill Coding Practices
- Location
scripts/register_file.py:134- Finding
Persistent Markdown Injection in the Inbox Index
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent local file inbox skill, but it needs review because it can move files by default and stores unsanitized file metadata in a persistent index that agents are told to read.
Review this skill before installing. Use it only in workspaces where moving files into an inbox is expected, prefer --copy when preserving originals matters, and treat inbox/INDEX.md as untrusted data if filenames, sender names, tags, or notes may come from other people.
scripts/register_file.py:134Persistent Markdown Injection in the Inbox Index
scripts/register_file.py:184Directory Paths Are Accepted by a File-Only Registration Operation
The declared description presents a general bidirectional file management system used to save user files, generate/send files, and find/list/search previously exchanged files. The supplied code chunk does not implement those core behaviors. Instead, it is a narrow reporting script that inspects an existing inbox directory, parses metadata and an index markdown table, measures directory sizes, and prints summary statistics such as totals, file types, tags, and recent activity. While this is related to the same inbox resource, its primary purpose is analytics/status display, not file management or retrieval. Therefore the description materially overstates and mischaracterizes what this code chunk actually does.
Without declared permissions the skill's intent is opaque and cannot be validated.
The script performs a move operation by default, which removes the file from its original location and is a user-data-affecting action. Although the usage text mentions 'move' as the default, there is no runtime confirmation prompt or explicit warning immediately before the operation in code.
No suspicious patterns detected.