T09 · Insecure Skill Coding Practices
- Location
nex-ghostwriter.py:401- Finding
Arbitrary Writable-File Overwrite Through Export Path Traversal
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but its export command can be abused to overwrite user-writable files outside its data folder.
Install only if you are comfortable storing meeting notes, contacts, drafts, and exports locally under ~/.nex-ghostwriter. Avoid exporting to user-supplied or untrusted filenames, and be cautious opening CSV exports in spreadsheet software until path validation and CSV formula neutralization are fixed.
nex-ghostwriter.py:401Arbitrary Writable-File Overwrite Through Export Path Traversal
lib/storage.py:395Spreadsheet Formula Injection in CSV Exports
The skill advertises shell execution, environment access, and file-writing behavior via setup and CLI usage, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates a trust-boundary problem: an agent may invoke shell/file-capable operations without a narrowly declared contract, increasing the chance of unintended command execution or filesystem modification if the skill is auto-selected or used with untrusted user input.
The trigger phrases include broad, common language such as 'draft an email', 'recap', 'meeting notes', and 'action items', which can cause the skill to activate in contexts the user did not intend. Because this skill can write files and invoke shell-backed commands, accidental invocation could persist sensitive meeting data locally or cause side effects without clear user consent.
The skill handles sensitive business data including meeting notes, attendee names, client emails, action items, deadlines, and exports, but the description and usage guidance do not prominently warn users up front that this information is stored locally. In practice, users may disclose confidential or regulated information without realizing it will be persisted on disk and exported into searchable files.
The export command builds the destination path from a user-supplied filename using EXPORT_DIR / output_file and then writes to it without validating that the resolved path stays inside the export directory. An attacker or untrusted local user could supply path traversal values such as ../../somefile or an absolute path to overwrite arbitrary files accessible to the process, which is especially risky because the exported content contains meeting notes, contacts, and email data.
The export command writes all meeting data to a file, which likely includes notes, attendee details, client names, and email addresses. While the code prints the destination after writing, there is no prior warning, confirmation, or descriptive comment/docstring alerting the user that potentially sensitive meeting data will be persisted to disk.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
done
if [[ "$(uname)" != MINGW* ]] && [[ "$(uname)" != MSYS* ]] && [[ "$(uname)" != CYGWIN* ]]; then
chmod 700 "$DATA_DIR" 2>/dev/null || true
fi
echo ""
No suspicious patterns detected.