T09 · Insecure Skill Coding Practices
- Location
SKILL.md:49- Finding
Predictable Shared Temporary File Enables Symlink-Based File Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This PRD review skill is coherent and purpose-aligned, but users should avoid its fixed temporary file path for sensitive documents.
Before installing or using this skill, treat uploaded PRDs as potentially sensitive. If you run the extraction command, change /tmp/prd.txt to a private secure temporary file or project-local path with restricted permissions, and delete the extracted text after review.
SKILL.md:49Predictable Shared Temporary File Enables Symlink-Based File Overwrite
The skill instructs the user/agent to extract uploaded .doc content and write the decoded text to /tmp/prd.txt. In this markdown description, there is no accompanying warning that the process creates a local plaintext copy of PRD contents, which could affect sensitive user data handling or local storage expectations.
No suspicious patterns detected.