T09 · Insecure Skill Coding Practices
- Location
scripts/aggregate_scan.py:66- Finding
Trusted Skill Names Can Bypass Security Findings Through Overbroad Allowlisting
- Content
View full analysis
bool: """Check if a finding matches an allowlist entry.""" category = finding.get("category", "") file_path = finding.get("file", "") for al_skill, al_category, al_file in ALLOWLIST: if al_skill == skill_name and al_category == category: if al_file is None or al_file in file_path: return True return False ``` The identity used for allowlist matching is derived only from the directory basename: ```python skill_name = os.path.basename(skill_dir) ``` Findings are then discarded before the verdict is recomputed: ```python if is_allowlisted(skill_name, f): continue ``` ### Technical Analysis The allowlist treats a directory name as proof of Skill identity. It does not verify the package's signature, trusted publisher, immutable digest, installation source, or expected file inventory. Entries whose file component is `None` suppress an entire finding category across every file in the named Skill. For `skill-defender`, this include ...[truncated 1755 chars]- Remediation
View remediation
