T09 · Insecure Skill Coding Practices
- Location
vetting.cjs:142- Finding
Documented subcommands are incorrectly interpreted as scan targets
- Content
View full analysis
!a.startsWith('-')) || '.'; // Resolve relative path if (!path.isAbsolute(targetPath)) { targetPath = path.resolve(process.cwd(), targetPath); } ``` The documented interface is: ```bash skill-vet scan /path/to/skill skill-vet scan /path/to/skill --verbose skill-vet check /path/to/skill ``` ### Technical Analysis The parser selects the first argument that does not begin with a hyphen and treats it as the target path. Under the documented interface, that argument is the `scan` or `check` subcommand rather than `/path/to/skill`. Consequently: - `skill-vet scan /path/to/skill` resolves `scan` relative to the current directory. - `skill-vet check /path/to/skill` resolves `check` relative to the current directory. - The intended target path is ignored. - If no corresponding local path exists, the program terminates with a path-not-found error. - If a local file or directory named `scan` or `check` exists, the scanner analyzes that object instead of the requested Skill. Because this tool is intended to act as a security gate before installation or execution, scanning the wrong target undermines the validity of its result. ### Attack Path 1. An attacker distributes a malicious Skill and instructs the user to vet it using the documented command: `skill-vet scan /path/to/malicious-skill`. 2. The command is run from a directory containing a benign file or directory named `scan`. 3. The argument parser selects `scan` as the target and ignores `/path/to/malicious-skill`. 4. The benign local object is scanned. 5. The user may incorrectly associate t ...[truncated 562 chars]- Remediation
View remediation
[--verbose]'); process.exit(2); } const positional = args.slice(1).filter(arg => !arg.startsWith('-')); if (positional.length !== 1) { console.error('Exactly one target path is required.'); process.exit(2); } let targetPath = positional[0]; ``` Additionally: 1. Reject unknown subcommands and unexpected positional arguments. 2. Keep options and positional arguments distinct. 3. Add automated tests for `scan`, `check`, relative paths, absolute paths, missing paths, and extra arguments. 4. Print the canonical target path before scanning and require downstream automation to associate results with that path. ]]>
