T09 · Insecure Skill Coding Practices
- Location
SKILL.md:55- Finding
Predictable Temporary File Path Allows Local File Clobbering
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 55–67
Vulnerability Type: Predictable temporary file and unsafe file creation
Risk Level: LowVulnerable code:
bash curl -sS -X POST http://127.0.0.1:8880/v1/audio/speech \ -H 'Content-Type: application/json' \ -d '{ "model":"tts-1-hd", "voice":"me", "input":"Quick cloned voice check.", "speed":1.25, "response_format":"mp3" }' \ --output /tmp/clone-test.mp3 file /tmp/clone-test.mp3Technical Analysis
The documented command writes its response to the fixed path
/tmp/clone-test.mp3. Because/tmpis normally shared and writable by local users, an attacker may create that path before the command runs, including as a symbolic link to another file.curl --outputopens the supplied path for writing and may follow a pre-existing symbolic link. The linked target can therefore be truncated or overwritten with the TTS response under the permissions of the user executing the Skill. The predictable name also causes repeated executions to overwrite an existing test clip.Attack Path
- A local attacker predicts that the Skill will use
/tmp/clone-test.mp3. - Before execution, the attacker creates a symbolic link at that path pointing to a file writable by the victim:
bash ln -s /path/to/victim-writable-file /tmp/clone-test.mp3 - The victim or AI Agent runs the documented
curlcommand. curlfollows the symbolic link and opens the target for writing.- The target is truncated or replaced with the generated audio response.
Exploitation requires local access to the same host and a target writable by the user running the command.
Impact Assessment
A successful attack can overwrite or corrupt files accessible to the executing user. It does not inherently grant additional privileges: the attacker cannot overwrite files that the executing user lacks permission ...[truncated 264 chars]
- A local attacker predicts that the Skill will use
- Remediation
View remediation
Remediation Suggestions
Create the output in a private, unpredictable temporary directory rather than using a fixed shared path:
bash tmpdir="$(mktemp -d)" || exit 1 trap 'rm -rf -- "$tmpdir"' EXIT output="$tmpdir/clone-test.mp3" curl --fail-with-body -sS \ -X POST http://127.0.0.1:8880/v1/audio/speech \ -H 'Content-Type: application/json' \ -d '{ "model":"tts-1-hd", "voice":"me", "input":"Quick cloned voice check.", "speed":1.25, "response_format":"mp3" }' \ --output "$output" && file -- "$output"Ensure
mktempsucceeds before proceeding, quote all path variables, and remove the temporary directory after use. Avoid running this workflow with elevated privileges. If a persistent output is required, require the user to select a destination and reject pre-existing symbolic links or unintended files.
