T09 · Insecure Skill Coding Practices
- Location
SKILL.md:327- Finding
Path Traversal Through Unvalidated Task IDs and Project Names
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 327-370
Vulnerability Type: Unvalidated path construction and path traversal
Risk Level: MediumVulnerable Code
The following is an English rendering of the relevant path-derivation and file-update instructions:
text Project name -> Automatically locate project directory through keyword mapping 1. Search the "Project Keywords" table in memory/quick-search/keyword-mapping.md 2. If present: use the mapped path directly 3. If absent: generate it using the default path rules novel/project-name/ -> novel project code/project-name/ -> code project design/project-name/ -> design project research/project-name/ -> research project Derived file paths: Project index: memory/project-index/{project-type}-project-index.md Type index: memory/type-index/{task-type}.md Task details: memory/task-flow/task-details/{task-ID}.md Content dir: {project-directory}/content/ Plan dir: {project-directory}/plans/ Title library: {project-directory}/plans/used-title-library.md Step 2: Update task details Construct path: memory/task-flow/task-details/{task-ID}.md Check whether the file exists Exists -> mark completed and append an execution record Missing -> create a new file containing basic information and an execution recordThe original instructions directly interpolate externally supplied values into paths, including:
text memory/任务流/任务详情/{任务ID}.md {项目目录}正文/ {项目目录}规划/Technical Analysis
The documented external interface accepts a task ID and project name, then derives writable file paths from those values. The Skill does not require:
- Strict validation of the task-ID format.
- Rejection of
..,/,\, absolute paths, control characters, or encoded separators. - Canonicalization of keyword-map destinations.
- Verification that the resolved path remains in ...[truncated 1921 chars]
- Remediation
View remediation
Remediation Suggestions
-
Enforce a strict task-ID allowlist before constructing any path:
regex ^TASK_(NOVEL|CODE|DESIGN|RESEARCH|SYSTEM)_[0-9]{8}_[0-9]{3}$ -
Reject project names and identifiers containing:
../or\- Absolute-path prefixes
- Null bytes or control characters
- Encoded path separators
- Platform-specific reserved path components
-
Resolve every generated path to its canonical absolute form and verify that it is contained under an explicitly approved root, such as the canonical task-details or projects directory.
-
Apply the same validation and containment checks to paths loaded from the keyword-mapping file. Mapping entries must be treated as untrusted data rather than trusted configuration.
-
Reject symbolic links or verify the final resolved target immediately before each write to prevent redirection outside the permitted root.
-
Use fixed path-joining APIs rather than string concatenation, and fail closed when path validation is inconclusive.
-
Require user confirmation before overwriting an existing file that is not the exact expected task record.
-
Add negative tests covering traversal sequences, absolute paths, mixed separators, encoded traversal, malicious keyword mappings, and symbolic-link targets.
-
