T09 · Insecure Skill Coding Practices
- Location
scripts/extract-skill.sh:94- Finding
Workspace Boundary Bypass Through Symbolic-Link Traversal
- Content
View full analysis
"$SKILL_PATH/SKILL.md" << TEMPLATE ``` ### Technical Analysis The script attempts to confine generated Skills to the current workspace by rejecting absolute output paths and paths containing `..`. These lexical checks do not account for symbolic links in existing path components. For example, `./skills` can be a symbolic link to an external directory. The path still passes both validation checks because it is relative and contains no `..` segment. Both `mkdir -p` and the subsequent shell redirection follow the symbolic link, causing `SKILL.md` to be created outside the intended workspace. The validation and write are also separate operations. Even if a path is checked before use, an attacker with concurrent access to the workspace could potentially replace a checked directory with a symbolic link before the file is written, creating a time-of-check to time-of-use race. ### Attack Path 1. An attacker gains control over, or can modify, the project workspace layout. 2. The attacker creates a symbolic link such as: ```bash ln -s /attacker-selected/writable/directory skil ...[truncated 1085 chars]- Remediation
View remediation
