T09 · Insecure Skill Coding Practices
- Location
scripts/organize_attachments.py:163- Finding
Attachment organizer destructively moves source files without enforced confirmation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/organize_attachments.py:163-164, 274-278
Related Documentation:SKILL.md:165-176, 196
Vulnerability Type: Destructive source mutation without an enforced confirmation or dry-run gate
Risk Level: MediumVulnerable Code
python ap.add_argument("--copy", action="store_true", help="复制(默认移动)")python # 落盘:解密件直接写字节,原文件按 --copy 复制/默认移动 if data is not None: try: target.write_bytes(data) except OSError as exc: print(f"[!] 写入失败 {target}: {exc}") continue elif args.copy: shutil.copy2(fp, target) else: shutil.move(str(fp), str(target))The documented invocation omits
--copy:bash python scripts/organize_attachments.py \ --src "$ACCOUNT/$SRC" \ --dst "<输出目录>/$SRC" \ --contact "$SRC"The documentation also states both that files are moved by default and that the source is read-only:
markdown - 默认移动文件,预览/试跑请加 `--copy`markdown - 源目录只读,解密产物只写 `--out` / `--dst`Technical Analysis
The
--copyoption is opt-in, so the default execution path callsshutil.move()for every matching plaintext attachment discovered recursively under--src. There is no interactive prompt, explicit confirmation parameter, dry-run requirement, or transaction-like rollback mechanism before source files are removed from their original locations.This behavior is particularly risky because the Skill's documented workflow invokes the script without
--copyand separately claims that the source directory is read-only. An agent following the documented command can therefore interpret the operation as nondestructive while the implementation relocates files from WeChat-managed storage.This is a real, reachable unsafe default rather than evidence of a backdoor or malicious intent.
Attack Path
- A user asks the Skill to organize or archive locally downloaded WeChat attachments.
- The agent follows the command documented in ` ...[truncated 1275 chars]
- Remediation
View remediation
Remediation Suggestions
- Make copying the default behavior and require an explicit option such as
--movefor source mutation. - Require a second explicit acknowledgement for destructive operation, such as:
bash --move --confirm-source-removal - Add a dry-run mode that lists every planned source and destination path without changing files.
- Before moving, display the normalized source and destination roots, the number of affected files, and the total data size.
- Reject overlapping source and destination directories to prevent recursive or inconsistent processing.
- Prefer a two-phase workflow: copy and verify hashes first, then remove source files only after successful verification and explicit confirmation.
- Handle partial failures with a manifest that supports rollback or safe resumption.
- Update
SKILL.mdso its read-only claims match the executable behavior. The standard documented command should include--copyunless the user explicitly requests source removal.
- Make copying the default behavior and require an explicit option such as
