T09 · Insecure Skill Coding Practices
- Location
SKILL.md:86- Finding
User-Controlled Path Traversal in Task Initialization
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 86–88 and 128–129
Vulnerability Type: Path traversal caused by an unsanitized customer identifier
Risk Level: Mediumbash TASK_NAME="quote-${CUSTOMER}-$(date +%Y%m%d)" mkdir -p ~/.workbuddy/tasks/"$TASK_NAME" cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF' ... touch ~/.workbuddy/tasks/"$TASK_NAME"/research-findings.md cat > ~/.workbuddy/tasks/"$TASK_NAME"/progress-log.md << 'EOF'Technical Analysis
The
CUSTOMERvalue is incorporated directly intoTASK_NAME, which is then used as part of several filesystem paths. Although quoting the variable prevents shell word splitting and direct shell-command injection, it does not neutralize path separators or traversal components such as../.If an untrusted party controls the customer name, a value containing traversal sequences can cause the resulting path to resolve outside the intended
~/.workbuddy/tasks/directory. The commands then create directories and write fixed-name files at the attacker-selected resolved location.Attack Path
- An attacker supplies a customer name containing path traversal components, such as multiple
../segments. - The agent assigns that unvalidated value to
CUSTOMER. - The documented initialization block constructs
TASK_NAMEfrom the malicious value. mkdir,cat, andtouchresolve the traversal components when operating on the generated paths.- The operations escape the expected task directory and create or overwrite
task-plan.md,progress-log.md, andresearch-findings.mdin another directory writable by the executing user.
Exploitation requires the agent to run the documented shell block with an attacker-controlled customer name.
Impact Assessment
The attacker does not gain additional operating-system privileges. File operations execute with the permissions of the user running the Skill.
Within that use ...[truncated 547 chars]
- An attacker supplies a customer name containing path traversal components, such as multiple
- Remediation
View remediation
Remediation Suggestions
- Convert the customer name to a strict filesystem-safe identifier before constructing
TASK_NAME. Allow only a narrow character set such as ASCII letters, digits, underscores, and hyphens. - Reject empty values,
.and.., path separators, control characters, shell metacharacters, and names exceeding a reasonable length. - Construct the destination from a fixed base directory and verify its canonical path remains beneath that base before performing any write.
- Create the task directory securely and fail if it already exists to reduce accidental or malicious overwrites.
- Avoid writing through symbolic links. Validate directory ownership and permissions, and use no-clobber or exclusive file-creation behavior where supported.
- Keep display names separate from filesystem identifiers so the original customer name never needs to be used as a path component.
Example hardening approach:
bash SAFE_CUSTOMER=$(printf '%s' "$CUSTOMER" | tr -cd 'A-Za-z0-9_-') [ -n "$SAFE_CUSTOMER" ] || { echo "Invalid customer identifier" >&2 exit 1 } BASE_DIR="$HOME/.workbuddy/tasks" TASK_NAME="quote-${SAFE_CUSTOMER}-$(date +%Y%m%d)" TASK_DIR="$BASE_DIR/$TASK_NAME" mkdir -p -- "$BASE_DIR" mkdir -- "$TASK_DIR" || exit 1Canonical containment and symbolic-link checks should additionally be applied before creating the output files.
- Convert the customer name to a strict filesystem-safe identifier before constructing
