T05 · Unauthorized Access and Privilege Escalation
- Location
script/package.py:24- Finding
Arbitrary Local File Read Through Unvalidated Package Paths
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill presents itself as an automated deployment packager, but its script can read arbitrary plan-supplied local paths and falsely reports live uploads without creating or uploading packages.
Do not use this in an unattended CI/CD deployment path unless it is fixed. It should validate package paths against a project-local allowlist, reject traversal and absolute paths, create and verify real archives, and only report upload success after a real copy/upload completes.
script/package.py:24Arbitrary Local File Read Through Unvalidated Package Paths
The skill text claims a narrowly scoped packaging/upload role, but the behavior implied by the findings includes extra file enumeration and manifest/checksum generation while not clearly implementing the stated archive/upload actions. This mismatch is risky because reviewers and operators may approve or invoke the skill under false assumptions, allowing broader file inspection or unexpected data handling in a deployment pipeline.
The script claims to create deployment bundles and upload them to shared storage, but in live mode it only constructs a target path, prints a success message, and writes a manifest. This is a security-relevant integrity issue because operators or downstream automation may trust the manifest and logs as evidence that deployable artifacts exist, enabling silent deployment failure, release confusion, or abuse of the false audit trail.
The skill describes file read/write style behavior but does not declare any explicit tool scope or permission boundaries. In an automated packaging/deployment context, missing scope constraints increases the chance that the agent can read unintended files or write artifacts outside the intended deployment area, especially when it is instructed to trust upstream input.
The skill explicitly directs unattended upload to a shared storage location accessible by all team members and CI/CD servers, while also stating that it trusts upstream packaging plans and skips re-audit or confirmation. In this context, a malicious or mistaken packaging plan could cause sensitive files, secrets, or non-deployment artifacts to be automatically published to a broadly accessible location, making exposure and downstream compromise more likely.
In live mode, the code logs '[LIVE] Uploaded' for a bundle path even though no tarball is created and no upload occurs. This misleading success signal can cause users or CI/CD systems to proceed under false assumptions, weakening operational trust and masking failed or missing release artifacts.
The file's user-facing description and operational instructions are entirely in Chinese, which can constitute a language/locale policy issue when no user opt-in or alternative is offered. There is no indication that the skill is region-specific or intentionally constrained to Chinese-speaking users.
No suspicious patterns detected.