T09 · Insecure Skill Coding Practices
- Location
SKILL.md:136- Finding
Predictable Executable Temporary File Enables Symlink and Replacement Attacks
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 136–142
Vulnerability Type: Predictable and insecure temporary-file handling
Risk Level: Mediumbash cat > /tmp/test-for-bug.sh << 'EOF' #!/bin/bash # Return 0 if bug is NOT present, 1 if it IS npm test -- --grep "login should redirect" 2>/dev/null EOF chmod +x /tmp/test-for-bug.sh git bisect run /tmp/test-for-bug.shTechnical Analysis
The documented workflow creates, modifies, and executes a script at the fixed, globally predictable path
/tmp/test-for-bug.sh. On a shared Unix-like system,/tmpis normally writable by all local users. Although its sticky bit restricts deletion of other users' files, it does not make predictable file creation safe.An attacker who can write to
/tmpmay pre-create the path as a symbolic link before the redirection occurs. If the user has permission to write to the symlink target,cat > /tmp/test-for-bug.shcan truncate and overwrite that target. The subsequentchmod +xmay also change the target's executable permissions.There is also a time-of-check/time-of-use window between script creation and
git bisect run. If an attacker can replace or influence the path during that interval,git bisectmay execute attacker-controlled commands with the privileges of the user following the instructions.Attack Path
- A local attacker predicts that the workflow will use
/tmp/test-for-bug.sh. - Before the victim runs the documented commands, the attacker creates that path as a symbolic link to a file writable by the victim, or prepares to replace the path after creation.
- The victim executes the redirection, potentially overwriting the linked target.
- The victim runs
chmod +x, potentially altering permissions on the unintended target. - Alternatively, the attacker replaces or modifies the script before
git bisect runexecutes it. - The victim executes the attacker-controlled script ...[truncated 539 chars]
- A local attacker predicts that the workflow will use
- Remediation
View remediation
Remediation Suggestions
Create an atomically allocated, user-private temporary directory and place the executable script inside it. Quote all path expansions, restrict script permissions, and register cleanup:
bash tmpdir="$(mktemp -d)" || exit 1 trap 'rm -rf -- "$tmpdir"' EXIT script="$tmpdir/test-for-bug.sh" cat > "$script" <<'EOF' #!/bin/bash # Return 0 if bug is NOT present, 1 if it IS npm test -- --grep "login should redirect" 2>/dev/null EOF chmod 700 "$script" git bisect run "$script"Additionally:
- Do not use a fixed filename directly under a shared temporary directory.
- Ensure
mktemp -dsucceeds before creating or executing any file. - Keep the temporary directory accessible only to its owner.
- Remove temporary artifacts through a quoted
trap, including on interruption or failure. - Where practical, keep the test script in the trusted repository instead of generating executable content in
/tmp.
