T09 · Insecure Skill Coding Practices
- Location
scripts/publish-article.sh:52- Finding
Predictable Temporary File Allows Symlink-Based File Clobbering
- Content
View full analysis
/tmp/x-article-snapshot.txt 2>&1 if ! grep -qi "contenteditable\|article\|editor" /tmp/x-article-snapshot.txt; then echo "Warning: Editor may not have loaded. Check browser." fi ``` ### Technical Analysis The script writes browser snapshot data to the fixed path `/tmp/x-article-snapshot.txt`. It does not securely create the file, verify its ownership, reject symbolic links, restrict its permissions, or remove it after use. On systems where symbolic-link protections do not block the operation, another local user can create this predictable path as a symbolic link to a file writable by the victim. Shell redirection follows the link and truncates the target before `agent-browser` runs. An attacker may also pre-create a permissively readable regular file at the expected path. If the victim can open that file for writing, the resulting browser snapshot may remain accessible to the attacker. Such snapshots can contain information from the authenticated X page. ### Attack Path 1. A local attacker predicts the fixed path `/tmp/x-article-snapshot.txt`. 2. The attacker creates that path as a symbolic link to a target writable by the intended victim, or creates an attacker-readable regular file at that location. 3. The victim executes `publish-article.sh`. 4. The shell opens the predictable path using output redirection. 5. In the symbolic-link case, the linked target is truncated and overwritten with browser output. 6. In the regular-file case, the attacker may read the snapshot after the script writes authenticated-page information to it. 7. The script does not clean up the temporary artifact. The feasibility of the symbolic-link variant depends on ...[truncated 541 chars]- Remediation
View remediation
"$SNAPSHOT_FILE" 2>&1 if ! grep -qi "contenteditable\|article\|editor" "$SNAPSHOT_FILE"; then echo "Warning: Editor may not have loaded. Check browser." fi ``` ]]>
