T09 · Insecure Skill Coding Practices
- Location
scripts/generate_group_def.js:109- Finding
Unsafe Command-Line Parsing May Overwrite the Node.js Executable
- Content
View full analysis
- Remediation
View remediation
= 0 && !process.argv[outputIndex + 1]) { throw new Error('--output requires a file path'); } const outPath = outputIndex >= 0 ? process.argv[outputIndex + 1] : 'group_def.json'; fs.writeFileSync(outPath, JSON.stringify(output, null, 2), { encoding: 'utf8', flag: 'wx' }); ``` Additional hardening should include: - Use a maintained command-line parser with required-value validation. - Reject output paths that resolve to directories or protected executables. - Consider requiring explicit confirmation before overwriting an existing file. - Use the `wx` flag when overwriting is not intended. - Never recommend executing this script with elevated privileges. - Add tests covering absent `--output`, a missing argument value, duplicate arguments, and an existing destination. ]]>
