T09 · Insecure Skill Coding Practices
- Location
scripts/generate_group_def.js:111- Finding
Incorrect Argument Parsing Can Overwrite the Node.js Executable
- Content
View full analysis
- Remediation
View remediation
= 0 && !process.argv[outputIndex + 1]) { throw new Error('The --output option requires a file path.'); } const outPath = outputIndex >= 0 ? process.argv[outputIndex + 1] : 'group_def.json'; fs.writeFileSync(outPath, JSON.stringify(output, null, 2), { encoding: 'utf8', flag: 'wx', }); ``` Additional hardening should include: 1. Use a maintained command-line parser with required-value validation. 2. Reject values beginning with `--` when they occur where an output path is expected. 3. Resolve the path and verify that it is within an approved output directory when arbitrary destinations are unnecessary. 4. Use the exclusive-create flag (`wx`) by default to prevent silently overwriting existing files. 5. Require an explicit overwrite option if replacement of an existing file is necessary. 6. Add tests covering an absent `--output`, a missing value, duplicate options, and protected or existing destinations. 7. Avoid running the generator with elevated privileges. ]]>
