T09 · Insecure Skill Coding Practices
- Location
SKILL.md:223- Finding
Unsanitized Student Identifier Enables Path Traversal
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 223-255
Vulnerability Type: Path traversal through a user-controlled filename
Risk Level: MediumVulnerable Code
markdown 1. **定学习者身份**:`student_id`?检查 `tutor_memory/<student_id>.md`:存在→载 L2/L3 跳步骤1;不存在→新建(L3 空模板 + L2 表头 + p 初始化 0.5)。markdown 3. **写文件**:Edit/Write 回 `tutor_memory/<student_id>.md`。The same unsafe path convention is initially defined at line 46:
markdown | **L2 掌握度矩阵** | 按知识点(KC)聚合:掌握概率 p + 状态 + 错误类型分布 + 证据 + 最近更新 | `tutor_memory/<student_id>.md` | 长期累积,随答随更新 |Technical Analysis
The Skill obtains
student_idfrom the user and interpolates it directly into a filesystem path used for both reading and writing. It does not require validation, canonicalization, separator rejection, or verification that the resolved path remains undertutor_memory/.A crafted identifier containing traversal sequences could therefore resolve outside the intended profile directory. For example,
../../noteswould produce:text tutor_memory/../../notes.mdWhether exploitation succeeds depends on the host Agent's filesystem permissions and any path-containment controls enforced by its file tools. The Skill itself provides no protective control.
Attack Path
- An attacker invokes the Skill and supplies a malicious student identifier, such as
../../existing-file. - The Agent constructs
tutor_memory/../../existing-file.md. - During initialization, the Agent checks whether that resolved path exists and may read it as though it were a student profile.
- During session closeout, the Agent follows the instruction to write updated profile data to the same path.
- If the host permits access, a Markdown file outside
tutor_memory/may be read, created, or overwritten.
Impact Assessment
Successful exploitation could provide unauthorized read or write access to files reachable by the Agent's filesystem permissions. Potential consequences inclu ...[truncated 457 chars]
- An attacker invokes the Skill and supplies a malicious student identifier, such as
- Remediation
View remediation
Remediation Suggestions
-
Restrict student identifiers to a conservative allowlist, such as:
regex ^[A-Za-z0-9_-]{1,64}$ -
Explicitly reject:
..path components.- Forward and backward slashes.
- Absolute paths.
- Drive prefixes.
- Null bytes and control characters.
- Encoded forms that decode into path separators or traversal components.
-
Resolve and canonicalize the destination path before every read or write, then verify that it remains beneath the canonical
tutor_memory/directory. -
Generate an opaque internal filename, such as a UUID or a cryptographic hash of the validated identifier, rather than using raw user input as a filename.
-
Refuse the operation if validation or containment verification fails; do not attempt to normalize an unsafe identifier silently.
-
Apply least-privilege filesystem permissions so the Agent can access only the dedicated profile directory where practical.
-
Add tests covering Unix and Windows traversal forms, absolute paths, mixed separators, encoded separators, excessively long identifiers, and filename collisions.
-
