T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Predictable Shared Temporary Directory Enables File Injection, Disclosure, and Destructive Cleanup
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:24-26
Additional Locations:SKILL.md:71-72,SKILL.md:81,SKILL.md:135-136
Vulnerability Type: Unsafe temporary-directory handling
Risk Level: MediumVulnerable Code
bash # SKILL.md:24-26 unzip -o document.docx -d docx_temp cd docx_temp && zip -r ../output.docx . && cd .. && rm -rf docx_tempThe same fixed directory is used elsewhere:
bash # SKILL.md:71-72 unzip -o document.docx -d docx_temp cat docx_temp/word/comments.xmlbash # SKILL.md:81 unzip -o document.docx -d docx_tempbash # SKILL.md:135-136 cd docx_temp && zip -r ../output.docx . && cd .. rm -rf docx_tempTechnical Analysis
The documented workflow extracts untrusted DOCX archives into a predictable directory named
docx_temp. It neither creates that directory securely nor verifies its ownership, contents, or isolation from another process. The-ooption overwrites existing files without confirmation.The repackaging command recursively archives everything in the directory, including stale or attacker-planted files that are not part of the current document. The final recursive deletion also acts on the shared predictable path without confirming that it is the directory created by the current operation.
This creates local race-condition and pre-positioning opportunities. Exploitation requires an attacker who can modify the working directory or race the workflow under the operating-system permissions of the user executing the commands.
Attack Path
- The attacker predicts that processing will use
./docx_temp. - Before extraction, the attacker creates or populates that directory with crafted or sensitive content. Alternatively, the attacker modifies it while processing is in progress.
- The instructed
unzip -ooperation writes into the attacker-influenced shared directory and silently overwrites colliding fil ...[truncated 1106 chars]
- The attacker predicts that processing will use
- Remediation
View remediation
Remediation Suggestions
- Create a unique private directory for every invocation with
mktemp -d. - Register a cleanup trap immediately after successful directory creation.
- Quote all path expansions.
- Verify that the cleanup target is nonempty, expected, and owned by the current process before recursive deletion.
- Reject archive entries with absolute paths or
..traversal components before extraction. - Repackage only explicitly expected OOXML files rather than recursively including every directory entry.
- Prevent concurrent runs from sharing extraction state.
- Consider using a DOCX/ZIP library that validates archive members and writes to a controlled destination.
Example hardened shell workflow:
bash tmpdir="$(mktemp -d)" || exit 1 cleanup() { if [ -n "${tmpdir:-}" ] && [ -d "$tmpdir" ]; then rm -rf -- "$tmpdir" fi } trap cleanup EXIT HUP INT TERM unzip -- document.docx -d "$tmpdir" ( cd -- "$tmpdir" || exit 1 zip -r -- ../output.docx \ '[Content_Types].xml' _rels docProps word )Archive member names should be validated before the extraction step because command quoting alone does not prevent malicious archive-entry traversal in vulnerable extraction tools.
- Create a unique private directory for every invocation with
