T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_status.py:19- Finding
Caller-Controlled Filesystem Paths Permit Writes Outside Intended Storage Directories
- Content
View full analysis
bool: try: os.makedirs(os.path.dirname(status_file), exist_ok=True) with open(status_file, 'w', encoding='utf-8') as f: json.dump(status, f, ensure_ascii=False, indent=2) return True except IOError: return False ``` Dataset storage similarly w ...[truncated 3676 chars]- Remediation
View remediation
/config` and `/data`. 3. Canonicalize every requested path before use and verify that it remains inside its permitted root: ```python from pathlib import Path PROJECT_ROOT = Path(__file__).resolve().parent.parent STATUS_ROOT = (PROJECT_ROOT / "config").resolve() DATA_ROOT = (PROJECT_ROOT / "data").resolve() def resolve_within(root: Path, supplied: str) -> Path: candidate = (root / supplied).resolve() if candidate != root and root not in candidate.parents: raise ValueError("Path escapes the permitted storage directory") return candidate ``` 4. Reject absolute paths, traversal components, null bytes, unexpected path types, and symbolic-link escapes. 5. Validate paths in both the Node.js entry point and Python code so the Python layer remains secure if called directly. 6. Use atomic status updates by writing to a temporary file inside the permitted directory and replacing the target only after a successful write. 7. Refuse to overwrite symbolic links and, where practical, existing files that are not recognized application-owned data. 8. Run the Skill under a dedicated low-privilege operating-system account with write access only to its designated data directories. 9. Add tests covering absolute paths, `../` traversal, symbolic links, malformed paths, and attempts to target files outside the project. ]]>
