T09 · Insecure Skill Coding Practices
- Location
scripts/generate_pages_batch.py:28- Finding
Arbitrary File Overwrite Through Output Filename Path Traversal
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real lead-generation website skill, but its generators and contact form have production-impacting safety gaps that users should review before installing.
Review before installing or using in production. Do not run the page generator on JSON or templates you did not author and trust; first add filename containment checks, schema validation, and context-aware escaping or structured rendering. Remove console logging of lead data, implement a real HTTPS submission backend, and show success only after confirmed delivery. Treat the bundled French/RGPD content as a starting point that still needs jurisdiction-specific legal and privacy review.
scripts/generate_pages_batch.py:28Arbitrary File Overwrite Through Output Filename Path Traversal
scripts/generate_pages_batch.py:22Generated TypeScript and TSX Code Injection Through Unescaped Template Substitution
scripts/create_seo_files.py:12Sitemap and Robots Content Injection Through Unvalidated SEO Metadata
templates/component-ContactForm.tsx:31Personal Lead Information Logged in Plaintext and False Submission Confirmation
The declared description presents a broad website-generation and compliance capability, including multi-page site creation, SEO optimization, conversion tracking, analytics, structured data, and RGPD compliance. The actual code chunk is much narrower: it simply creates robots.txt and sitemap.xml files from supplied inputs. While this fits a small part of 'SEO optimization,' it does not support the larger declared purpose and omits most of the described functionality. There is no evidence of undeclared harmful behavior, but there is a clear description-versus-behavior mismatch because the code only implements a limited SEO file generation utility rather than a complete local lead generation website builder.
The code chunk is a narrow utility that transforms an input JSON spec into a Markdown outline of site content. While this loosely relates to website planning and includes some SEO-related fields like title, meta description, and H1, it does not implement the declared end-to-end capability of building complete local lead generation websites. It also lacks any functionality for conversion tracking, analytics, structured data generation, or RGPD compliance. The actual behavior is substantially narrower than the declared purpose, so this is a material description-behavior mismatch.
The declared description promises a full local lead-generation website builder with SEO, analytics/conversion tracking, structured data, and RGPD compliance features. The supplied code only implements a generic batch templating utility: it loads a template and JSON data, replaces placeholders, and writes output files. While batch page generation could support website creation, the primary behavior here is much narrower and lacks the key advertised capabilities. This is a material description-behavior mismatch.
Referenced artifact was not completely inspected
**Header** (`templates/component-Header.tsx`):
Referenced artifact was not completely inspected
**Header** (`templates/component-Header.tsx`):
The README promotes conversion tracking and UTM collection for lead generation workflows but does not explicitly warn about personal data implications, lawful basis, consent requirements, or data minimization. In the context of local lead-gen sites that collect contact details and marketing attribution, this omission can lead implementers to deploy privacy-impacting tracking in a non-compliant way.
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill instructs collection of UTM attribution parameters in the contact form and says they can be sent to a backend/CRM, but it does not require a clear user-facing notice, consent basis, or data-minimization rules. In a lead-generation and GDPR context, silent capture and downstream transmission of tracking metadata can create privacy, compliance, and trust risks, especially when linked to personal contact details.
The document explicitly recommends collecting personal data through forms and capturing UTM parameters for attribution, but it does not pair that guidance with any privacy notice, consent, retention, or lawful-basis requirements. In a lead-generation skill that also claims RGPD compliance, this omission can lead builders to implement tracking and contact collection in a way that violates privacy expectations and data protection obligations.
This file contains user-facing instructional content exclusively in French, which can violate language/locale policy when no opt-in, alternative language, or explicit regional justification is provided. The content appears generally applicable rather than clearly limited to a French-speaking or region-specific compliance context.
The document directs operators to collect customer photos/videos and maintain weekly conversation logs containing location, symptoms, objections, and entry-page tracking data, but it does not provide any data-minimization, consent, retention, access-control, or redaction guidance. In a WhatsApp-based lead qualification workflow, these materials can contain personal data and even sensitive contextual details about a person's home, creating privacy, compliance, and data-handling risk if reused for SEO/Ads insights.
The generated content headings and labels are hard-coded in French, which imposes a specific language/locale on all output. The file does not offer a user opt-in or configuration for language selection, nor does it document a justified region-specific constraint.
The form collects personal data and marketing attribution fields in a lead-generation/RGPD-oriented context, but the submission handler only writes the data to the browser console and clears the form. This creates a misleading data-handling flow that can result in lost leads and non-compliant processing expectations, especially because users are induced to submit contact information without any real backend processing or privacy handling.
The handler logs user-supplied personal data including name, phone, email, message, and UTM metadata to the browser console. Console logging of PII can expose sensitive data to anyone with local browser access, shared-device users, support/debug tooling, or captured logs, and it is especially problematic in an RGPD/compliance-oriented lead form.
The success toast states that the user will be contacted soon, but no request is sent, stored, or queued anywhere. In a lead-capture website, this is dangerous because it deceives users into believing a service request was received when it was silently discarded, potentially causing business loss and privacy/compliance complaints.
This component presents all user-facing consent text and actions in French only, including the banner title, description, and buttons. That can violate language/locale policy when no user opt-in or documented regional scope is provided.
The visible UI labels are hard-coded in French (for example, 'Contacter via WhatsApp' and 'Appeler maintenant') without any indication that the skill is French-only or that users can choose a language. This is a natural-language locale policy concern because the file imposes a specific language by default.
Le README indique que des images sont générées puis stockées dans /home/ubuntu/webdev-static-assets/, ce qui décrit une opération d'écriture sur le système de fichiers. Le document n'indique pas explicitement ce comportement comme potentiellement modifiant l'environnement local ni ne conseille de vérifier le contenu existant ou les permissions avant exécution.
La ligne indique que les templates sont en français et seulement 'facilement traduisibles', ce qui suggère une langue par défaut imposée plutôt qu'un choix explicite offert à l'utilisateur. La politique demande de signaler les contraintes de langue ou de locale lorsqu'elles ne sont pas présentées comme un opt-in ou comme une limitation clairement justifiée.
The overview line introduces French-language requirements and phrasing ('avec garde-fous anti-spam', etc.), and later sections continue using French-specific terminology and deliverables. Because the skill does not explicitly offer a language/locale choice, it may impose a specific language or locale convention without user opt-in.
This markdown file contains operational guidance exclusively in French, and there is no note that the skill is intended only for French-speaking users or that another language can be selected. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale policy issue.
The examples for value propositions and CTA text are written in French, which can imply a fixed language preference in skill guidance. Because the file does not state that it is intended only for a French-speaking or region-specific audience, this may conflict with the policy against forcing a specific language without user opt-in or justification.
This markdown file contains user-facing instructions exclusively in French, starting with 'Objectif' and continuing throughout the playbook. Under the policy rule for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue when no justification or language choice is provided.
Line L31 states "Legal Mentions (Required in France)" in a generally titled compliance guide, which introduces a jurisdiction-specific requirement without clearly limiting the document's scope to France-only use. This can be read as imposing a locale-specific policy on all users of the skill content rather than offering it as a conditional requirement based on deployment region.
The document title, instructions, and copy/paste message are all in French, and the template at L13-L18 assumes French-only interaction. Per SQP-3, forcing a specific language without user opt-in can violate language/locale policy unless the regional limitation is explicitly documented and justified, which is not stated here.
No suspicious patterns detected.