T09 · Insecure Skill Coding Practices
- Location
scripts/download.sh:7- Finding
Path Traversal Allows Filesystem Modification and Potential Recursive Deletion
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi ``` 2. Create the working directory with `mktemp` under a dedicated parent: ```bash DOWNLOAD_ROOT="$HOME/Downloads" WORK_DIR=$(mktemp -d "$DOWNLOAD_ROOT/.m3u8-download.XXXXXX") ``` 3. Register cleanup with a trap and only remove the directory returned by `mktemp`: ```bash cleanup() { [[ -n "${WORK_DIR:-}" && -d "$WORK_DIR" ]] && rm -rf -- "$WORK_DIR" } trap cleanup EXIT INT TERM ``` 4. Canonicalize and verify all destination paths remain under the expected download root before writing or deleting them. 5. Reject path separators, traversal components, control characters, and symbolic-link targets in caller-controlled output names. 6. Avoid unconditional overwrite behavior where possible, or require explicit caller confirmation before replacing an existing output file. ]]>
