T09 · Insecure Skill Coding Practices
- Location
scripts/seven_steps.py:40- Finding
Path Traversal Enables Arbitrary JSON File Read and Overwrite
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a real estate marketing framework, but its helper script can read or overwrite JSON files outside its own project folder if given a crafted project name.
Review this skill before installing if you plan to use the Python helper. Avoid untrusted or unusual project names, especially names containing slashes, backslashes, drive prefixes, or '..', because the current script does not confine project files to its intended state/projects directory. The methodology documents themselves appear purpose-aligned.
scripts/seven_steps.py:40Path Traversal Enables Arbitrary JSON File Read and Overwrite
Without declared permissions the skill's intent is opaque and cannot be validated.
The trigger terms are broad marketing phrases like '营销策划', '项目定位', and '传播策略' that can match many ordinary business conversations, causing the skill to activate outside the author's intended context. Overbroad activation can inject unsolicited domain-specific guidance into unrelated chats, increasing the chance of context confusion, workflow disruption, or accidental use when sensitive business discussions are occurring.
The entire template is written in Chinese and presents a fixed-language structure for the skill artifact, with no indication that users may request another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
The module description, docstrings, templates, usage text, and runtime messages are all presented only in Chinese, which imposes a specific language without any visible opt-in or alternative. Under the stated policy, language constraints should either be user-selectable or clearly documented as a justified locale-specific limitation.
This code creates a JSON file under the state/projects directory and writes project content to it, but the function itself provides no prompt, warning, or explanatory comment that user data will be persisted locally. The same pattern appears elsewhere in the file, indicating the skill performs file writes that could affect user data without clear disclosure at the point of operation.
The save_project function writes the full project object back to the project's JSON file, replacing prior contents, but there is no confirmation prompt or user-facing warning about overwriting stored data. Because this changes persisted project state, it is a safety-relevant file write lacking visible disclosure in the code path.
The file includes an English overview, but the core description and the full operational content are primarily in Chinese and do not state that the user can choose their preferred language. This can amount to a locale/language policy issue when a skill implicitly defaults to one language without opt-in.
This markdown guide presents all instructions and content exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. The policy requires avoiding forced language or locale constraints unless the choice is offered or the limitation is clearly justified.
No suspicious patterns detected.