T09 · Insecure Skill Coding Practices
- Location
scripts/generate-script.sh:154- Finding
Predictable Plaintext Prompt Storage with Symlink-Following File Write
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate-script.sh, lines 154-157
Vulnerability Type: Predictable plaintext storage and unsafe file write
Risk Level: MediumVulnerable Code
bash # Also save the prompt to a file for reference PROMPT_FILE="${SKILL_DIR}/references/last-prompt.txt" mkdir -p "$(dirname "$PROMPT_FILE")" BUILD_PROMPT > "$PROMPT_FILE"The stored prompt is assembled from user-controlled CLI parameters parsed at lines 52-58 and interpolated by
BUILD_PROMPTat lines 88-102:bash --topic) TOPIC="$2"; shift 2 ;; --duration) DURATION="$2"; shift 2 ;; --style) STYLE="$2"; shift 2 ;; --audience) AUDIENCE="$2"; shift 2 ;; --product) PRODUCT="$2"; shift 2 ;; --points) SELLING_POINTS="$2"; shift 2 ;; --cta) CTA="$2"; shift 2 ;;bash BUILD_PROMPT() { echo "请生成一个抖音短视频脚本,主题:${TOPIC}" echo "时长:${DURATION}秒" echo "风格:${STYLE}" echo "目标受众:${AUDIENCE}" if [[ -n "$PRODUCT" ]]; then echo "产品:${PRODUCT}" fi if [[ -n "$SELLING_POINTS" ]]; then echo "卖点:${SELLING_POINTS}" fi if [[ -n "$CTA" ]]; then echo "行动号召(CTA):${CTA}" fiTechnical Analysis
Every non-JSON invocation automatically writes the generated prompt to the fixed package-relative path
references/last-prompt.txt. The persisted data can include topics, target audiences, unpublished product information, selling points, and campaign calls to action.This persistence is not required to print or generate the prompt and is performed without explicit user consent. The implementation does not establish restrictive file permissions, create the file atomically, prevent concurrent overwrites, or verify that the destination is a regular file rather than a symbolic link.
Standard shell redirection follows symbolic links. Therefore, an attacker who can modify the package directory or the existing destination can replace
references/last-prompt.txtwith a symbolic link. A later invo ...[truncated 1591 chars]- Remediation
View remediation
Remediation Suggestions
- Do not persist generated prompts by default. Print the prompt to standard output and require an explicit option such as
--output PATHbefore writing it. - Clearly disclose that the output may contain sensitive user-supplied information and obtain explicit user intent before storing it.
- If automatic caching is essential, place files in a user-private directory created with mode
0700, and create files with mode0600. - Reject symbolic-link destinations. Open a newly created file with exclusive-creation and no-follow semantics through a suitable helper rather than ordinary shell redirection.
- Use a unique per-invocation filename and atomic creation to avoid cross-user leakage and concurrent overwrite races.
- Verify that any user-selected destination is an expected regular file and that its parent directory is trusted.
- Define a retention policy and securely remove cached prompts when they are no longer needed.
- Avoid executing the skill with elevated privileges when its installation directory or output location is writable by less-trusted users.
- Do not persist generated prompts by default. Print the prompt to standard output and require an explicit option such as
