T09 · Insecure Skill Coding Practices
- Location
scripts/prompt-vc.sh:144- Finding
Path Traversal Through Unvalidated Prompt Names
- Content
View full analysis
/dev/null || true [ -z "$name" ] && die "Usage: prompt-vc.sh add [--template type] [--description ...]" while [ $# -gt 0 ]; do case "$1" in --template) template="$2"; shift 2 ;; --description) description="$2"; shift 2 ;; *) shift ;; esac done local prompt_file="$PROMPT_DIR/prompts/${name}.yaml" [ -f "$prompt_file" ] && die "Prompt '${name}' already exists at ${prompt_file}" local system_text user_text case "$template" in chat) system_text="You are a helpful AI assistant. Respond concisely and accurately." user_text="{{query}}" ;; classifier) system_text="You are a text classifier. Analyze the input and classify it into the appropriate category." user_text="Classify the following: {{input}}" ;; generator) system_text="You are a content generator. Create high-quality output based on the given prompt." user_text="Generate: {{prompt}}" ;; extractor) system_text="You are an information extractor. Extract structured data from unstructured text." user_text="Extract from: {{text}}" ;; custom) system_text="" user_text="{{input}}" ;; *) die "Unknown template: $template (use: chat|classifier|generator|extractor|custom)" ;; esac cat > "$prompt_file" <- Remediation
View remediation
