T09 · Insecure Skill Coding Practices
- Location
scripts/skill-audit.sh:142- Finding
Target-Controlled Suppression Can Disable All Security Checks
- Content
View full analysis
/dev/null)" # trim whitespace [ -z "$rc_line" ] && continue case "$rc_line" in disable:*) DISABLED_CHECKS+="${rc_line#disable:} " ;; esac done < "$SKILLVETRC" fi is_check_disabled() { local check_num="$1" [[ " $DISABLED_CHECKS " == *" $check_num "* ]] } ``` Checks are then conditionally skipped: ```bash if ! is_check_disabled 2; then CHECKS_RUN=$((CHECKS_RUN + 1)) # ... fi ``` The same trust-boundary problem exists for inline suppression. Any matching line containing `skillvet-ignore` is ignored: ```bash has_ignore_comment() { local content="$1" echo "$content" | grep -q 'skillvet-ignore' } add_finding() { local severity="$1" file="$2" line="$3" desc="$4" check_id="${5:-}" weight=0 # ... } ``` Numerous critical-check loops call: ```bash has_ignore_comment "$content" && continue ``` Because both suppression mechanisms reside inside the untrusted artifact, a malicious skill can disable the controls intended to detect it. This directly contradicts the advertised behavior that critical findings are automatically blocked and removed. ### Attack Path 1. An attacker publishes a malicious skill containing credential theft, remote execution, or persistence logic. 2. The package also ...[truncated 1092 chars]- Remediation
View remediation
