T09 · Insecure Skill Coding Practices
- Location
src/index.js:126- Finding
Path Traversal Enables Arbitrary JSON File Read, Deletion, and Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This decision logger is mostly purpose-aligned, but a path-handling bug could let its view, update, or delete functions affect JSON files outside its own storage folder.
Review before installing. The skill does not show hidden remote code, exfiltration, install hooks, or deceptive instructions, but it should validate decision IDs and enforce directory containment before view/update/delete are safe. Avoid recording secrets or highly sensitive planning details unless local file permissions are hardened, and prefer a fixed version that stores files with owner-only permissions and has clear retention/deletion behavior.
src/index.js:126Path Traversal Enables Arbitrary JSON File Read, Deletion, and Overwrite
src/index.js:26Decision Records Are Created Without Explicit Restrictive Permissions
The skill is designed to persist user-provided decision records across sessions in local storage, and those records may contain sensitive technical, product, team, or personal planning rationale. Session persistence is a genuine privacy/security concern here because retained records can expose confidential context, strategic decisions, or personal information if stored without clear consent, retention guidance, or access protections.
## Core capabilities
- Detect decision-oriented text
- Create structured decision records
- Search and filter past decisions
- Review decision details
- Analyze decision patterns
The skill explicitly supports deleting stored decision records but does not warn users that invoking the delete command can permanently remove locally stored data under ~/.decision-recorder/. This is a real safety/usability weakness because an agent could surface or invoke destructive functionality without making the irreversible consequence clear, increasing the risk of unintended data loss.
This code presents help text entirely in Chinese and formats dates with a hard-coded 'zh-CN' locale, which imposes a specific language/locale on all users. The file does not offer any opt-in, configuration, or documented justification for this locale restriction.
The skill persists potentially sensitive decision content to a fixed local directory in the user's home folder without any notice, consent flow, or visibility at the point of collection. Because decision records may contain product plans, internal rationale, credentials accidentally pasted by users, or personal notes, silent local persistence creates a privacy and data-handling risk, especially in an agent context where users may not expect durable storage.
The delete function irreversibly removes a decision record as soon as it is called, with no confirmation, soft-delete, or recovery mechanism. In an agent-driven workflow, mistaken invocation, prompt confusion, or misuse by another component can lead to loss of potentially important historical rationale and auditability.
The package description is written entirely in Chinese, which indicates a fixed language choice in user-facing metadata without offering any language or locale option. Under the policy, forced language presentation without user opt-in can be a natural-language policy violation unless clearly justified as region-specific.
The file embeds Chinese-language naming, messages, and keyword triggers together with English equivalents, but does not indicate any user-selectable language or locale preference. Because the skill behavior is partially tied to fixed language choices, this may violate a policy requiring language/locale opt-in rather than implicit enforcement.
No suspicious patterns detected.