T09 · Insecure Skill Coding Practices
- Location
scripts/export.py:47- Finding
Glob Injection Allows Unintended Cross-Session Transcript Selection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This looks like a legitimate Codex session exporter, but it needs Review because it can read and export sensitive past transcripts and some safeguards are incomplete.
Install only if you are comfortable with the skill reading local Codex history. Use explicit session IDs, avoid wildcard-like values, prefer --brief and --redact, and manually review exported files before sharing because metadata such as session IDs and workspace paths may remain. Pin install versions or inspect the source package instead of relying on npx/latest commands.
scripts/export.py:47Glob Injection Allows Unintended Cross-Session Transcript Selection
scripts/export.py:497Redaction Mode Leaves Sensitive Session Header Metadata Unmasked
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Referenced artifact was not completely inspected
python3 scripts/export.py --list
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
改动以“小步提交”落在功能分支上,每一条提交都是独立回滚单元:
1. **功能分支回滚**(未合并):直接 `git reset --hard <合并前基线>`,或删除分支重建。
2. **合并后回滚**:`git revert <提交号>` 逐个还原;提交按需求映射可精确定位(见上文表格)。
3. **对照原版**:已配置 upstream(`jinghan23/codex-export`),可用 `git diff upstream/main` 查看与官方版本的差异。
4. **数据安全**:导出文件与检查点(`*.state.json`)均为生成物,不进入代码库;回滚不影响已导出的对话文件。
The skill documentation appears to require Chinese comprehension for installation, usage, and safety-relevant behavior such as redact/export options. Under the natural-language policy rule, forcing a specific language without user opt-in is a policy violation unless the locale constraint is clearly documented and justified.
The README instructs users to run npx codex-export-more without pinning a specific package version. This causes execution of whatever version is current in the registry at install time, increasing supply-chain risk if a malicious or compromised release is published later. In a skill context, users may copy-paste this command directly, making the exposure more practical.
The command npx clawhub@latest install codex-export-more explicitly tracks the latest version, which is unpinned and can change over time. If the upstream package is hijacked, compromised, or releases a malicious update, users following the README could execute attacker-controlled code during installation. Because this is framed as a recommended install path for a skill, the context makes the supply-chain risk more actionable.
The skill appears to require environment access plus file read/write capabilities, but it does not declare an explicit tool scope or permissions boundary. That increases the chance the agent invokes the skill with broader-than-expected access, especially because the skill exports local session transcripts that may contain secrets, file paths, and tool outputs.
The invocation description is broad enough to match common requests such as save, share, review, or export a past chat, which can trigger the skill in situations where the user did not intend transcript extraction. In this context, accidental activation is meaningful because the skill handles historical conversation data that may include sensitive content.
The documentation promotes exporting session contents without a prominent warning that transcripts may include secrets, personal data, internal system/developer messages remnants, tool outputs, or local paths. Even though a --redact option exists, making it optional rather than strongly recommended or default increases the risk of users sharing sensitive data unintentionally.
The file begins with a Chinese-only title and the entire development guidance is written in Chinese, with no indication that language selection is optional or that the locale is intentionally restricted for a region-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.
The publish instructions use npx clawhub@latest install codex-export-more, which resolves and executes the latest package from the registry at install time rather than a pinned, reviewed version. If the upstream package is compromised, typo-squatted, or publishes a malicious update, users following the docs could execute attacker-controlled code during installation.
The HTML renderer hard-codes Chinese UI strings such as "会话信息", "用户", and sets the document language to "zh-CN". This imposes a specific locale on all users without offering a language choice or documenting a justified region-specific constraint.
The note says the skill works on "Windows/zh-CN," which references a specific locale, but it does not actually require or force output in that locale. Because this appears to be compatibility documentation rather than a mandated locale setting, the concern is limited and lower confidence.
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
Detected: suspicious.dangerous_exec