T09 · Insecure Skill Coding Practices
- Location
skillscan/detectors.py:18- Finding
Pattern-based detection and severity scoring can misclassify dangerous skills
- Content
View full analysis
&|" r"/dev/tcp/|" r"mkfifo\s+|" r"chmod\s+[0-7]*777|" r"rm\s+-rf\s+/)", ) DETECTORS: list[tuple[str, re.Pattern[str]]] = [ ("credential_harvesting", _CREDENTIAL_RE), ("data_exfiltration", _EXFIL_RE), ("obfuscated_command", _OBFUSCATED_RE), ("permission_overreach", _OVERREACH_RE), ] TOTAL_PATTERNS = len(DETECTORS) def scan(content: str) -> list[str]: """Scan SKILL.md content and return list of detected threat names.""" return [name for name, pattern in DETECTORS if pattern.search(content)] ``` Related scoring logic: ```python findings = scan(request.skill_content) num_matched = len(findings) if num_matched == 0: safety_score = Decimal("1") else: safety_score = ( 1 - Decimal(num_matched) / Decimal(TOTAL_PATTERNS) ).quantize(Decimal("0.0001"), rounding=ROUND_HALF_UP) ``` ### Technical Analysis The service determines whether a submitted skill is safe using four narrow regular expressions. These expressions operate directly on unnormalized text and do not parse shell syntax, Python, JavaScript, URLs, or other executable constructs. The exfiltra ...[truncated 2742 chars]- Remediation
View remediation
