T09 · Insecure Skill Coding Practices
- Location
scripts/audit_worker.py:338- Finding
Unrestricted File Deletion Through --delete-after-read
- Content
View full analysis
Vulnerability Details
File Location:
scripts/audit_worker.py:338-383
Vulnerability Type: Arbitrary caller-selected file deletion
Risk Level: HighVulnerable Code
python parser.add_argument('--file', help='Read content from file instead of stdin') parser.add_argument('--text', help='Inline text to scan (WARNING: visible in process list)') parser.add_argument('--delete-after-read', action='store_true', help='Delete the --file after reading (for temp-file workflow)')python elif args.file: try: with open(args.file, 'r', encoding='utf-8') as f: text = f.read(read_limit) except OSError as exc: print(f'[ERROR] Cannot read file {args.file}: {exc}', file=sys.stderr) sys.exit(1) if args.delete_after_read: try: os.remove(args.file) except OSError as exc: print(f'[WARN] Could not delete temp file {args.file}: {exc}', file=sys.stderr)Technical Analysis
The
--fileoption accepts an unrestricted filesystem path. When--delete-after-readis present, the worker deletes that path without verifying that it is a temporary file created specifically for the scan.The implementation does not:
- Restrict deletion to a dedicated temporary directory.
- Verify that the file was created or is owned by the current workflow.
- Reject symbolic links or non-regular files.
- Canonicalize the path and enforce containment within an approved root.
- Require separate authorization for deletion of an existing file.
- Delay deletion until input validation and scan processing have succeeded.
Consequently, the option provides a general file-deletion primitive for any file that the process can read and delete.
Attack Path
- An attacker, untrusted automation input, or confused Agent influences the
--file...[truncated 921 chars]
- Remediation
View remediation
Remediation Suggestions
- Create temporary scan files inside a dedicated private directory controlled by the worker.
- Record securely created temporary files and only allow deletion of paths present in that record.
- Resolve the candidate path and verify that it remains beneath the approved temporary root.
- Reject symbolic links, directories, devices, and other non-regular files.
- Open files using platform-appropriate no-follow protections where available.
- Prefer accepting an already-open file descriptor instead of reopening and deleting a caller-supplied pathname.
- Perform deletion only after successful input validation and processing.
- Separate scanning from deletion authorization so that reading a file does not implicitly authorize its destruction.
- Add tests proving that paths outside the temporary root and symbolic-link targets cannot be deleted.
