T09 · Insecure Skill Coding Practices
- Location
SKILL.md:90- Finding
Predictable Shared Temporary Kubeconfig Path Enables Credential Disclosure and File Overwrite
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 90–95
Vulnerability Type: Predictable insecure temporary file containing sensitive credentials
Risk Level: Highbash cat > /tmp/kubeconfig.yaml <<'EOF' [KUBECONFIG_YAML] EOF # Set KUBECONFIG environment variable export KUBECONFIG=/tmp/kubeconfig.yamlTechnical Analysis
The documented workflow writes a Kubernetes kubeconfig to the fixed, globally predictable path
/tmp/kubeconfig.yaml. Kubeconfig files can contain bearer tokens, client private keys, client certificates, and other credentials.Shell redirection follows symbolic links. A local attacker can therefore create
/tmp/kubeconfig.yamlas a symbolic link before the workflow is executed. The redirection would truncate and replace the linked destination if the user running the command has permission to write to it. If no link exists, the permissions of the newly created file depend on the user's currentumask; the workflow does not explicitly require mode0600.Attack Path
- A local attacker predicts the documented
/tmp/kubeconfig.yamlfilename. - The attacker either monitors the path for a permissively created file or creates a symbolic link at that path to a file writable by the victim.
- The user or agent follows the Skill instructions and redirects kubeconfig content into the predictable path.
- If a symbolic link is present, the shell follows it and overwrites the target. Otherwise, an insufficiently restrictive
umaskmay make the kubeconfig readable to other local users. - The attacker obtains Kubernetes credentials or causes corruption of another victim-writable file.
Impact Assessment
Exposed credentials allow access with the identity and RBAC permissions contained in the kubeconfig. Depending on that identity, the impact can include reading cluster resources, accessing Kubernetes Secrets, modifying workloads, or administering the cluster. ...[truncated 200 chars]
- A local attacker predicts the documented
- Remediation
View remediation
Remediation Suggestions
- Replace the fixed path with a securely generated file created by
mktemp. - Set
umask 077before creating any credential-bearing file. - Ensure the file is newly created and is not a symbolic link.
- Explicitly enforce mode
0600, for example withinstall -m 600. - Register an exit trap to remove temporary kubeconfig files:
bash umask 077 KUBECONFIG_FILE="$(mktemp)" trap 'rm -f -- "$KUBECONFIG_FILE"' EXIT HUP INT TERM - Avoid placing long-lived credentials in a shared temporary directory where possible.
- Replace the fixed path with a securely generated file created by
