T09 · Insecure Skill Coding Practices
- Location
SKILL.md:99- Finding
Predictable Shared Temporary File Enables Local File Overwrite and Data Exposure
- Content
View full analysis
/tmp/args.json mcporter call tencent-docs create_smartcanvas_by_mdx --args "$(cat /tmp/args.json)" ``` The same fixed-path workflow is repeated in `references/platform-compat.md:54-58`. ### Technical Analysis The documented workflow writes translated document content to the predictable shared path `/tmp/args.json`. Shell output redirection opens this path without exclusive creation, ownership verification, or an explicit restrictive permission mode. In a multi-user environment, another local account can anticipate the filename and attempt to pre-create it as a symbolic link or otherwise manipulate the path before the workflow runs. If operating-system symbolic-link protections do not block the operation, redirection follows the link and truncates or overwrites the linked file with the privileges of the user running the Skill. The generated file contains the complete Markdown document passed through `--rawfile mdx "$FILE"`. Its permissions depend on the process umask. An insufficiently restrictive umask may therefore expose translated content to other local users. The workflow also does not remove the temporary file after upload, leaving document content on disk. This issue does not itself grant arbitrary elevated privileges. The attacker is limited to files writable by the victim process, and successful symbolic-link exploitation may be constrained by platform protections such as Linux `fs.protected_symlinks`. ### Attack Path 1. An attacker with local access observes or infers that the Skill always uses `/tmp/args.json`. 2. Before the victim executes the upload workflow, ...[truncated 1281 chars]- Remediation
View remediation
"$ARGS_FILE" || exit 1 mcporter call tencent-docs create_smartcanvas_by_mdx \ --args "$(cat -- "$ARGS_FILE")" ``` Additional hardening measures: 1. Replace every documented use of `/tmp/args.json`, including the duplicate workflow in `references/platform-compat.md`. 2. Use `mktemp` rather than constructing a temporary filename manually. 3. Set `umask 077` before creation so only the current user can read or modify the file. 4. Install a cleanup trap so sensitive document content is deleted on success, failure, or interruption. 5. Check the exit status of `jq` and stop before invoking the upload command if JSON generation fails. 6. If supported by the upload tool, pass JSON through standard input and avoid writing document content to disk entirely. 7. Where a temporary file remains necessary, verify that it is a regular file owned by the current user before reading it. ]]>
