T09 · Insecure Skill Coding Practices
- Location
SKILL.md:36- Finding
Hard-Coded Personal Output Directory Enables Unintended File Access and Overwrite
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 36
Vulnerability Type: Unsafe hard-coded filesystem path and insufficient output isolation
Risk Level: MediumVulnerable Code Snippet
The following is a faithful English translation of the complete rule at the affected location:
markdown 8. **Output path:** User-specified path → validate it as an absolute path without `..` and ensure it does not point to a system directory → fall back if validation fails. Default path: `/Users/afeng/Documents/侯佳男/华夏基金2026/NLP_Learn/.claude/skills/99-写作(小说、剧本)/95-短篇小说/03-大女主/danuzhu-novel-master/assets/output`.The continuation workflow later instructs the agent to scan the selected directory, read existing outlines and chapters, and write or overwrite generated Markdown and TXT files there.
Technical Analysis
The Skill uses a developer-specific absolute directory as its default output location whenever the user does not provide another path. This directory is outside the installed project and exposes a personal username and private directory structure.
The path checks only reject relative traversal and a small set of system directories. They do not enforce a trusted output root, resolve and validate symbolic links, verify ownership, or require approval before reading and modifying an existing external directory. Because the continuation workflow treats existing files as prior state, the agent may read unrelated files from that location and incorporate their contents into later model processing.
The Skill also states that intermediate drafts are overwritten rather than versioned. If the hard-coded directory exists and contains files with expected names, generated content can replace those files. The issue does not independently grant operating-system privileges; exploitation is limited to the filesystem permissions already held by the executing agent.
Attack Path
- A user invokes the novel-generation S ...[truncated 1556 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the developer-specific absolute path with a project-relative output directory resolved from the installed Skill root.
- Define a dedicated allowed output root and reject every path whose canonicalized form falls outside that root.
- Resolve symbolic links before authorization checks and repeat validation immediately before file access to reduce link-swap risks.
- Require explicit user confirmation before scanning, reading, or modifying an existing directory outside the project workspace.
- Use non-destructive, collision-safe filenames by default. Require explicit approval before replacing an existing file.
- Write through securely created temporary files and perform an atomic rename only after successful generation.
- Create backups or use versioned output files when continuation mode modifies existing work.
- Remove personal usernames and private directory structures from distributed configuration and documentation.
- Restrict continuation scanning to known extensions and expected file patterns under the validated output root.
- Add tests covering path traversal, symbolic links, output collisions, external absolute paths, and failed canonicalization.
