T09 · Insecure Skill Coding Practices
- Location
SKILL.md:70- Finding
Predictable Shared Temporary File for Generated Audio
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 70-81
Vulnerability Type: Unsafe temporary-file handling
Risk Level: LowComplete Code Snippet:
bash curl -s https://api.openai.com/v1/audio/speech \ -H "Authorization: Bearer $OPENAI_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "model": "tts-1-hd", "input": "<news summary text>", "voice": "onyx", "speed": 0.95 }' \ --output /tmp/news.mp3Technical Analysis
The voice-generation workflow writes its result to the fixed, predictable path
/tmp/news.mp3. Temporary directories are commonly shared by multiple users and processes. Reusing a known filename creates opportunities for file collisions, cross-run interference, and symbolic-link attacks.If the execution environment permits following attacker-created symbolic links in
/tmp, another local process could create/tmp/news.mp3as a link to a different file before the command runs. Thecurl --outputoperation could then truncate or overwrite that target under the privileges of the account executing the Skill. Some operating systems mitigate this scenario through protected-symlink settings, but the Skill should not rely exclusively on platform-specific protections.Independently of symbolic-link protections, concurrent Skill executions can overwrite the same output, expose one invocation's generated audio to another invocation, or cause the wrong audio file to be sent to a user.
Attack Path
- A local attacker or competing process predicts that the Skill will write to
/tmp/news.mp3. - Before voice generation begins, it creates a conflicting file or, where platform protections allow, a symbolic link at that path.
- The Skill invokes
curland writes the generated audio to the attacker-controlled filesystem entry. - The operation overwrites the conflicting file or follows the symbolic link to another file writable by th ...[truncated 723 chars]
- A local attacker or competing process predicts that the Skill will write to
- Remediation
View remediation
Remediation Suggestions
- Create a unique temporary file or private temporary directory for each invocation using
mktemp. - Apply restrictive permissions with
umask 077so only the executing account can access generated audio. - Validate that temporary-file creation succeeds before passing the path to
curl. - Remove the generated file through a cleanup trap when processing completes.
- Avoid reusing temporary paths across users, sessions, or concurrent executions.
- Where supported, use exclusive file creation and reject symbolic links.
Example hardened workflow:
bash umask 077 tmp_dir="$(mktemp -d)" || exit 1 trap 'rm -rf -- "$tmp_dir"' EXIT output_file="$tmp_dir/news.mp3" curl --fail --silent --show-error \ https://api.openai.com/v1/audio/speech \ -H "Authorization: Bearer $OPENAI_API_KEY" \ -H "Content-Type: application/json" \ -d '{ "model": "tts-1-hd", "input": "<news summary text>", "voice": "onyx", "speed": 0.95 }' \ --output "$output_file"- Create a unique temporary file or private temporary directory for each invocation using
