T09 · Insecure Skill Coding Practices
- Location
SKILL.md:203- Finding
Automatic Anonymous Exposure of the Current Working Directory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:119-141, 203-209, 359-382
Vulnerability Type: Unauthenticated remote file exposure
Risk Level: HighVulnerable Code
markdown > **CRITICAL — Zero confirmation during tunnel creation.** Execute the entire flow > (check CLI → load adaptation layer → check auth → create tunnel → configure port > → start hosting) fully automatically with ZERO user interaction. | Anonymous access | Allowed (`--anon allow`) |bash db_port_create <tunnelId> -p <port> --protocol <protocol> --anon allowbash nohup python3 -m http.server <port> > /tmp/devbridge-service.log 2>&1 & nohup db_host <tunnelId> > /tmp/devbridge-host.log 2>&1 &The same document acknowledges the resulting boundary:
markdown - **Anonymous access** means anyone with the tunnel address can access the port without DevBridge identity. Enable only for explicitly public content.Technical Analysis
The workflow combines three security-sensitive defaults:
- It prohibits confirmation during tunnel creation.
- It enables anonymous tunnel access by default.
- It automatically starts
python3 -m http.serverwithout specifying a safe document root.
By default, Python's HTTP server serves files from its current working directory. Consequently, a request to create a development tunnel can cause the agent to expose the directory from which it executes, rather than only forwarding a local service explicitly selected by the user.
The use of
--anon allowmeans the remote endpoint does not enforce DevBridge identity authentication. This contradicts the document's own instruction that anonymous access should be enabled only for explicitly public content.The attacker-controlled point is the unauthenticated HTTP request made by any remote party that obtains the generated tunnel address. The trust boundary is crossed when files in the agent's local working directory become remotely retrievab ...[truncated 1467 chars]
- Remediation
View remediation
Remediation Suggestions
- Default tunnel ports to authenticated access and require an explicit request before using anonymous access.
- Do not automatically start
python3 -m http.serveras part of generic tunnel creation. - Require the user to identify the exact existing local service to expose.
- If file serving is specifically requested, require an explicit document root and invoke:
bash python3 -m http.server "$PORT" --directory "$APPROVED_DIRECTORY" - Validate that the approved directory does not contain credential files, repository metadata, private keys, or application secrets.
- Display the selected local service, document root, protocol, access policy, and public URL before enabling unauthenticated access.
- Make anonymous access opt-in rather than opt-out.
- Reconcile the workflow with the existing security statement that anonymous access is only appropriate for explicitly public content.
