T09 · Insecure Skill Coding Practices
- Location
scripts/extract-skill.sh:97- Finding
Output Directory Boundary Bypass Through Symbolic Links
- Content
View full analysis
"$SKILL_PATH/SKILL.md" << TEMPLATE ``` ### Technical Analysis The script attempts to constrain output to the current directory by rejecting absolute paths and paths containing `..`. These checks validate only the lexical path supplied by the caller. They do not resolve the path to its canonical filesystem destination or detect symbolic links in existing path components. Consequently, an accepted relative path can resolve outside the current working directory. For example, if `./skills` is a symbolic link to `/tmp/external-skills`, the default destination `./skills/example-skill/SKILL.md` passes both validation checks but resolves to `/tmp/external-skills/example-skill/SKILL.md`. Both `mkdir -p` and shell redirection follow symbolic links. The script therefore does not enforce its documented requirement that the output directory remain under the current directory. The existing-directory check reduces the likelihood of overwriting an already existing skill directory, but it does not prevent creation through a symlinked parent. It also does not provide protection against a time-of-check/time-of-use replacement of path components in a concurrently controlled workspace. ### Attack Path 1. An attacker controls or prepares the workspace in which the script will run. 2. The at ...[truncated 1571 chars]- Remediation
View remediation
