T09 · Insecure Skill Coding Practices
- Location
scripts/present-design.py:429- Finding
Presentation server exposes files beyond the selected review artifacts
- Content
View full analysis
None: if self.current_target and 200 <= code < 400: with requested_lock: requested.add(self.current_target) super().send_response(code, message) handler = functools.partial(ReviewHandler, directory=str(root)) ``` ### Technical Analysis The server builds an `allowed` set containing the selected review artifact names, but that set is only used to update request-tracking state. It does not enforce authorization. Every non-control request is passed to `SimpleHTTPRequestHandler.do_GET()`. Because the handler is configured with the artifact parent directory as its document root, any readable file beneath that directory may be served, not only the HTML files explicitly supplied to `present-design.py serve`. The server binds to `127.0.0.1`, which limits remote exposure under ordinary conditions, but any local process, browser extension, forwarded loopback port, or user sharing the host can request adjacent files while the server is running. Directory listing may also be available through the inherited handler behavior. This exceeds the minimum access needed for the declared functionality, which only requires serving the selected review artifacts and their intentionally referenced assets. ### Attack Path 1. A review HTML artifact is stored in a directory that also contains source maps, configuration data, generated reports, or other non-public files. 2. The user or Agent runs: ```bash python3 scripts/present-design.py serve path/to/direction.html ``` 3. The server uses the artifact's parent directory as the HTTP document root. ...[truncated 956 chars]- Remediation
View remediation
