T09 · Insecure Skill Coding Practices
- Location
src/index.js:172- Finding
Path Traversal Enables Arbitrary JSON File Read, Export, Deletion, and Creation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly matches its purpose, but unsafe path handling can let snapshot commands read, copy, create, or delete JSON files outside the intended folder.
Review before installing. Use only trusted snapshot IDs and trusted import files, avoid sharing exports until you inspect them for local paths and environment details, and avoid delete/import/export commands on untrusted input until snapshot ID validation and path containment are fixed.
src/index.js:172Path Traversal Enables Arbitrary JSON File Read, Export, Deletion, and Creation
The documentation substantially overstates what the skill restores and manages, while also underemphasizing the real import capability from external paths. That mismatch is dangerous because users may trust it to safely preserve/recover session state, or may import untrusted data expecting benign behavior, leading to incorrect security assumptions and accidental disclosure or unsafe workflow decisions.
Referenced artifact was not completely inspected
} = require('./src/index.js');
The skill documents capabilities that capture environment data and host/session metadata, but the manifest shown in SKILL.md does not declare any tool scope or permissions boundary. In an agent ecosystem, missing scope declarations reduce transparency and policy enforcement, making it easier for a seemingly harmless context tool to access or expose sensitive runtime information without explicit user awareness.
A tool presented as a context-preservation helper also captures and exports host runtime metadata such as PATH, HOME, USER, shell, PID, and platform details. In this skill context, that makes the behavior more dangerous because users are likely to treat snapshots as harmless collaboration artifacts, when they may actually disclose sensitive environment and system profiling information.
The manifest description and opening documentation force Chinese-language interaction/content presentation, and the file does not offer an opt-in or alternative language. Under the policy, language constraints should be optional or explicitly justified as region-specific.
The skill advertises automatic snapshotting and import/export without prominently warning that environment and session metadata are written to disk and may later be shared. In this context-preservation skill, that omission materially increases risk because the normal user workflow involves saving and exporting data, making inadvertent disclosure of local operational context more likely.
The documentation claims snapshots store only context metadata, but the sample format includes environment variables and process identifiers, which are often sensitive operational data. This contradiction can mislead users into exporting or sharing snapshots that contain secrets, usernames, paths, or infrastructure details they did not realize were being preserved.
The manifest description forces a specific language in user-facing text and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This may violate language/locale policy for natural-language content.
This code includes natural-language documentation and command output exclusively in Chinese, indicating a fixed language choice for the skill. The policy requires flagging language or locale constraints when the skill does not offer user choice or clearly justify the restriction.
Snapshot creation persists host metadata including PATH, HOME, USER, SHELL, cwd, PID/PPID, and platform details to disk. While not immediately exploitable by itself, this unnecessarily broad collection increases exposure of sensitive local environment information, especially when snapshots are later exported, shared, or read by other local users/processes.
The tool writes user/system environment details to disk without a warning, consent flow, or data-classification notice. In the context of a 'context-preserver' skill, silent persistence is more dangerous because users may reasonably assume only conversation state is saved, not host metadata that can reveal usernames, directory layout, shells, and execution context.
The manifest and module header claim recovery/restore behavior, which implies reinstating prior context or session state. In practice, restoreSnapshot only loads a JSON file and logs fields like cwd, tags, and Node version; it does not change the working directory, restore environment variables, or rehydrate any conversation/session context.
Inline documentation labels this function as “恢复快照” and the CLI help advertises “restore <id|number> 恢复快照,” which conveys an operational restore action. The implementation only reads the snapshot file and prints its contents, creating an intent-code contradiction rather than mere incompleteness.
The deleteSnapshot function unlinks the snapshot file immediately with fs.unlinkSync and only logs after deletion. There is no confirmation prompt, pre-deletion warning, or documented notice that the operation is destructive and irreversible.
This is a manifest file, so vague-trigger checks apply. The description lists broad capabilities like automatic snapshotting, on-demand restore, session recovery, and context export, but provides no explicit trigger phrases, scope limits, or exclusion conditions, which can make invocation boundaries unclear.
The skill's title, help text, logs, and date formatting are all hard-coded in Chinese, including explicit locale formatting with toLocaleString('zh-CN'). This imposes a specific language/locale on all users without offering opt-in, selection, or a documented region-specific constraint.
The file uses Chinese natural-language strings throughout comments and console output, including the test suite title and all test names. For a general-purpose skill test file, this imposes a specific language/locale without any opt-in or justification, which matches the language-policy concern in SQP-3.
No suspicious patterns detected.