T09 · Insecure Skill Coding Practices
- Location
scripts/cloud_cli.py:13- Finding
Unrestricted Local File Content Upload Through Listing Arguments
- Content
View full analysis
str: """CLI argument: if it is an existing file path, read the file; otherwise treat it as text.""" raw = (value or "").strip() if not raw: return "" path = Path(raw) if path.is_file(): return path.read_text(encoding="utf-8") return raw ``` ```python # scripts/run.py:40-47 payload: dict = { "platform": args.platform, "lang": args.lang, "our_product": args.our_product.strip(), "competitor": read_text_arg(args.competitor), } if args.our_listing: payload["our_listing"] = read_text_arg(args.our_listing) data = run_skill(SKILL_API_ID, payload, timeout=180.0) ``` ### Technical Analysis The documented purpose of `--competitor` and `--our-listing` is to accept pasted listing text or a `.txt` file. However, `read_text_arg()` does not enforce a file extension, permitted directory, maximum size, regular-file policy, or explicit user approval. Any path that resolves to a readable file is interpreted as listing content. The resulting content is placed into the request payload and transmitted by `run_skill()`. This creates a local-file disclosure primitive when an untrusted party can influence the arguments issued by an Agent or automation layer. The behavior exceeds the minimum local-file privileges necessary for processing ordinary listing text files. The function does not bypass operating-system access controls: it can only read files available to the user account running the Skill. Nevertheless, that account may have access to source code, configuration files, API credentials, personal documents, or other information unrelated to competitor analysis. ### Attack Path 1. An attacker supplies a ...[truncated 1273 chars]- Remediation
View remediation
