T09 · Insecure Skill Coding Practices
- Location
SKILL.md:230- Finding
Predictable Temporary File Enables Symlink Attacks and Content Tampering
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 230–240
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Mediumbash **Recommended: Use a file** ```bash # Write JSON to file first echo '{"content":"Hello @friend! 🦞"}' > /tmp/molt.json # Send with -d @filename curl -X POST https://moltter.net/api/v1/molts \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ -d @/tmp/molt.jsonTechnical Analysis
The documented command writes post content to the fixed, predictable path
/tmp/molt.json. Shared temporary directories are commonly writable by multiple local users. The example neither securely creates the file nor verifies that it is a regular file owned by the current user. It also does not set restrictive permissions or delete the file afterward.Shell redirection follows symbolic links. Consequently, a local attacker may pre-create
/tmp/molt.jsonas a symbolic link to another file writable by the victim. Theechocommand would then truncate and overwrite that target. An attacker able to access the shared temporary directory may also replace or modify the JSON file between the write and the subsequentcurlread, creating a time-of-check/time-of-use race.Attack Path
- A local attacker anticipates that a user or agent will run the documented commands.
- The attacker creates
/tmp/molt.jsonas a symbolic link to a file writable by that user, or waits for the temporary file to be created. - The victim runs the
echo ... > /tmp/molt.jsoncommand. - If the path is a symbolic link, shell redirection follows it and truncates or overwrites the linked target.
- Alternatively, the attacker replaces or edits
/tmp/molt.jsonafterechocompletes but beforecurlopens it. - The authenticated
curlrequest publishes the attacker-modified content using the victim agent's API key.
This path requires local access to the same host and suitable filesystem timing or permis ...[truncated 785 chars]
- Remediation
View remediation
Remediation Suggestions
Avoid creating a temporary file and send the payload through standard input:
bash curl -X POST https://moltter.net/api/v1/molts \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ --data-binary @- <<'EOF' {"content":"Hello @friend! 🦞"} EOFIf a temporary file is necessary, create it atomically with
mktemp, apply restrictive permissions, and guarantee cleanup:bash tmp_file="$(mktemp "${TMPDIR:-/tmp}/molt.XXXXXXXXXX")" || exit 1 trap 'rm -f -- "$tmp_file"' EXIT chmod 600 "$tmp_file" cat >"$tmp_file" <<'EOF' {"content":"Hello @friend! 🦞"} EOF curl -X POST https://moltter.net/api/v1/molts \ -H "Authorization: Bearer YOUR_API_KEY" \ -H "Content-Type: application/json" \ --data-binary @"$tmp_file"For stronger isolation, create a private temporary directory with
mktemp -d, set its mode to700, place the payload inside it, and remove the directory on exit. Documentation should not recommend fixed filenames in shared writable directories.
