T09 · Insecure Skill Coding Practices
- Location
scripts/wget.py:3- Finding
Unrestricted URL Schemes and Arbitrary File Overwrite
- Content
View full analysis
[-O output]"); sys.exit(1) urllib.request.urlretrieve(url, output or os.path.basename(url)) print("Downloaded") ``` ### Technical Analysis The script passes the supplied URL directly to `urllib.request.urlretrieve` without validating its scheme. Although `SKILL.md` declares support for HTTP, HTTPS, and FTP downloads, the implementation does not enforce that protocol boundary. Python URL handlers may accept local resources such as `file://` URLs, allowing the script to copy files readable by its operating-system account. The output value is also passed directly to `urlretrieve` without restricting it to an approved download directory. A caller who controls the arguments can consequently select an absolute path or a path containing traversal components and replace a writable file. There is no existing-file check, overwrite confirmation, canonical-path boundary check, or symlink defense. The custom `-O` parser is defective because it enumerates `sys.argv[1:]` but reads `sys.argv[i+3]`. Normal documented usage such as `wget.py URL -O output` raises `IndexError`. Because unknown options are silently ignored and later positional arguments replace the URL, a crafted argument sequence can nevertheless assign both a chosen output and a chosen source. ### Attack Path 1. The attacker obtains control over arguments supplied to the downloader. 2. The attacker supplies a local `file://` URL instead of a documented network URL. 3. The attacker crafts the unusual argument order needed by the broken parser, for example: ```bash python3 scripts/wget.py -O --dummy ...[truncated 1338 chars]- Remediation
View remediation
