T09 · Insecure Skill Coding Practices
- Location
SKILL.md:88- Finding
Unsanitized Topic Allows Path Traversal and File Overwrite
- Content
View full analysis
~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF' # 任务计划 - 内容生产 ## 🎯 目标 完成 {主题} 的多平台内容生产+分发 ## 📋 步骤 - [ ] Phase 1: 选题策划(优先级:高) - 输入:主题/关键词 - 处理:热点追踪+爆款公式 - 输出:内容框架 - [ ] Phase 2: RAG检索(优先级:高) - 输入:内容框架 - 处理:IMA知识库检索 - 输出:历史爆款参考 - [ ] Phase 3: 内容创作(优先级:高) - 输入:内容框架+RAG结果 - 处理:content-factory - 输出:多平台内容 - [ ] Phase 4: 封面设计(优先级:中) - 输入:内容标题 - 处理:guizang-social-card - 输出:多平台封面图 - [ ] Phase 5: 多平台分发(优先级:中) - 输入:内容+封面 - 处理:social-auto-upload - 输出:发布链接 ## ✅ 验收标准 1. AI痕迹检测通过(anti-ai-slop) 2. 平台尺寸合规 3. 含行动号召(转化预期) 4. 品牌调性一致 ## 📅 时间线 - 创建时间:{ISO8601} - 预计完成:{日期} - 实际完成:{日期} EOF touch ~/.workbuddy/tasks/"$TASK_NAME"/research-findings.md cat > ~/.workbuddy/tasks/"$TASK_NAME"/progress-log.md << 'EOF' # 进度日志 - 内容生产 ## ✅ 已完成 (任务启动后填充) ## 🔄 进行中 - [ ] Phase 1: 选题策划(预计 $(date +%Y-%m-%d) 完成) ## 🚨 阻塞 (如有问题和解决方案,在此记录) ## 📍 下一步 1. 选题策划 2. RAG检索 3. 内容创作 4. 封面设计 5. 多平台分发 EOF ``` ### Technical Analysis The externally influenced `TOPIC` value is incorporated directly into `TASK_NAME`, which is then used as a directory component for multiple filesystem operations. Although quoting the variable prevents ordinary shell metacharacter injection, it does not prevent pathname traversal. A topic containing slash characters and `..` components can cause the constructed path to resolve outside the intended `~/.workbuddy/tasks` directory. The commands then: - Recursively create directories using `mkdir -p`. - Create or update `research-findings.md` using `touch`. - Truncate and overwrite `task-plan.md` and `progress-log.md` using `cat >`. The fixed `content-` prefix and date suffix constrain which paths can be selected, but they do not eliminate traversal. An ...[truncated 1907 chars]- Remediation
View remediation
&2 exit 1 } TASK_NAME="content-${SAFE_TOPIC}-$(date +%Y%m%d)" ``` 2. **Validate the canonical destination** - Canonicalize both the task root and destination before writing. - Verify that the destination remains a descendant of the canonical task root. - Abort if canonicalization reveals traversal outside that root. 3. **Use a securely created task directory** - Prefer `mktemp -d` under the trusted task root rather than constructing a directory solely from user-controlled text. - Use the sanitized topic only as a descriptive component. ```bash TASK_ROOT="$HOME/.workbuddy/tasks" mkdir -p -- "$TASK_ROOT" TASK_DIR=$(mktemp -d "$TASK_ROOT/content-${SAFE_TOPIC}-$(date +%Y%m%d)-XXXXXX") ``` 4. **Prevent unintended overwrites** - Enable no-clobber behavior with `set -o noclobber`, or explicitly test for existing files before redirecting. - Require confirmation before replacing any existing task record. - Open files using mechanisms that reject symbolic links where supported. 5. **Apply least privilege** - Run the Skill with access limited to its designated workspace. - Align the declared permissions with actual behavior, because the documented workflow performs filesystem writes even though the metadata only declares `file-read` and `network-access`. ]]>
