T09 · Insecure Skill Coding Practices
- Location
SKILL.md:82- Finding
Private Rule Files Are Not Protected from Accidental Git Disclosure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:82-84
Related Locations:references/custom-rules-template.yaml:2-3,README.md:56,140,README_CN.md:56,140
Vulnerability Type: Missing version-control exclusion for locally stored private rules
Risk Level: MediumVulnerable Code and Configuration
SKILL.md:82-84:text Private rules are used to hold company, team, and personal preferences. If a Skill with the same name exists in the workspace, use the workspace <SKILL_HOME> first; otherwise use the currently loaded Skill directory. The default directory is <SKILL_HOME>/rules/, with files company.yaml, team.yaml, and personal.yaml. The "list rules" operation must echo the actual rule file paths read. Missing files are skipped. The rule format and examples are in references/custom-rules-template.yaml. Private rules must not downgrade high_sensitive warnings in the public mapping library; attempts to do so must be rejected. Private rules must not be committed, packaged, or copied into public examples. Rule management is entered only when the user explicitly invokes an add, list, modify, disable, or delete rule command. Before writing, display the proposed change and wait for confirmation.references/custom-rules-template.yaml:2-3:yaml # Save locations: <SKILL_HOME>/rules/company.yaml, team.yaml, personal.yaml # <SKILL_HOME> is the directory containing this Skill. These files are private user data and must be excluded from Git, archives, and external deliverables.README.md:56,140:text Company, team, and personal preferences live under a local rules/ directory ignored by Git. Public releases never bundle organizational or personal rules.text Private rules remain local, are ignored by Git, and are excluded from public releases.No
.gitignorefile exists in the audited project, so the documented Git exclusion is not implemente ...[truncated 2471 chars]- Remediation
View remediation
Remediation Suggestions
-
Add a committed
.gitignorefile at the project root:gitignore rules/ -
If the repository needs to preserve the directory structure, use a safe placeholder:
gitignore rules/* !rules/.gitkeepCommit only an empty
rules/.gitkeepfile. -
Add a pre-publication or CI check that fails if private rule files are tracked:
bash if git ls-files 'rules/*.yaml' | grep -q .; then echo "Private rule files must not be tracked." exit 1 fi -
Before writing a rule, verify that the destination is under the intended
<SKILL_HOME>/rules/directory and that the repository's effective ignore configuration covers the file. -
Prefer storing private rules in a user-specific configuration directory outside the Git working tree. If this design is adopted, document the platform-specific location and migrate existing files safely.
-
Retain the existing explicit confirmation and content-validation controls, but clarify that they supplement rather than replace filesystem and version-control isolation.
-
Update README privacy claims only after testing that
git check-ignore rules/company.yamlconfirms effective exclusion.
-
