T09 · Insecure Skill Coding Practices
- Location
SKILL.md:156- Finding
Backup Failure Can Be Mistaken for Success Before Destructive File Operations
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 156–173
Vulnerability Type: Unverified backup operation and unconditional success reporting
Risk Level: MediumVulnerable Code
markdown > 💡 **此步骤仅为展示,无需等待用户确认,直接继续后续步骤。** ### 第三步:备份桌面 **macOS/Linux**: ```bash BACKUP_DIR="${BACKUP_PREFIX}$(date +%Y%m%d_%H%M%S)" cp -r "$DESKTOP_PATH/" "$BACKUP_DIR" echo "备份完成:$BACKUP_DIR"Windows:
powershell $BACKUP_DIR = "$BACKUP_PREFIX$(Get-Date -Format 'yyyyMMdd_HHmmss')" Copy-Item -Path "$DESKTOP_PATH\*" -Destination "$BACKUP_DIR" -Recurse Write-Host "备份完成:$BACKUP_DIR"备份成功后才可继续。
text ### Technical Analysis The Unix and Windows workflows report that the backup completed without checking whether the copy operation succeeded. The Unix example does not inspect the exit status of `cp`, enable fail-fast behavior, or validate the destination after copying. The PowerShell example does not use `-ErrorAction Stop`, explicitly create and validate the destination, or verify that all source entries were copied. Its wildcard source can also omit hidden items, contradicting the stated requirement to back up the complete desktop. The workflow subsequently proceeds to bulk file movement. Because the pre-check explicitly requires no user confirmation and the README describes the process as fully automatic, a partial or failed backup can be treated as valid before potentially destructive changes are made. ### Attack Path 1. The desktop contains an unreadable, locked, hidden, or otherwise uncopyable item, or the backup destination cannot be created due to storage or permission errors. 2. `cp` or `Copy-Item` fails or copies only part of the desktop. 3. The next command unconditionally prints a backup-success message. 4. The automated workflow continues to move desktop files and folders. 5. If a move fails, data is accidentally deleted later, or the user attempts restoration, the backup may not contain the required data. This is primarily a fa ...[truncated 643 chars]- Remediation
View remediation
Remediation Suggestions
-
Abort immediately when any backup command fails.
bash BACKUP_DIR="${BACKUP_PREFIX}$(date +%Y%m%d_%H%M%S)" if ! cp -a -- "$DESKTOP_PATH" "$BACKUP_DIR"; then echo "Backup failed; organization aborted." >&2 exit 1 fi -
For PowerShell, create the destination explicitly and convert non-terminating copy errors into terminating errors.
powershell $ErrorActionPreference = "Stop" $BACKUP_DIR = "$BACKUP_PREFIX$(Get-Date -Format 'yyyyMMdd_HHmmss')" try { New-Item -ItemType Directory -Path $BACKUP_DIR -ErrorAction Stop | Out-Null Get-ChildItem -LiteralPath $DESKTOP_PATH -Force | Copy-Item -Destination $BACKUP_DIR -Recurse -Force -ErrorAction Stop } catch { Write-Error "Backup failed; organization aborted: $_" exit 1 } -
Verify the backup before moving anything. Compare source and destination entry counts and sizes, and use hashes for important regular files where feasible.
-
Include hidden entries in the backup and avoid wildcard semantics that silently exclude them.
-
Check available disk space and destination writability before copying.
-
Print a success message only after the copy and verification stages both complete successfully.
-
Display the verified backup path and inventory to the user and request confirmation before beginning bulk moves.
-
Ensure every later move operation also checks errors and stops safely instead of continuing after a partial organization.
-
