T09 · Insecure Skill Coding Practices
- Location
medic_tools/run.py:1210- Finding
Indirect Prompt Injection Through Untrusted Skill and Web Content
- Content
View full analysis
str: """ Collect Skill "implementation declaration" text (tool-layer py + SKILL.md + agents/protocols + references/mcp-reference.md) for static resource-reference comparison. """ tool_texts: list[str] = [] body_texts: list[str] = [] if os.path.isdir(skill_dir): for entry in sorted(_safe_listdir(skill_dir)): if not is_tools_dir(entry) or entry == "medic_tools": continue tp = os.path.join(skill_dir, entry) if not os.path.isdir(tp): continue try: tool_files = os.listdir(tp) except OSError as e: print(f"Warning: unable to read tool directory {tp}: {e}") continue for f in tool_files: if f.endswith(".py") and f != "__init__.py": fp = os.path.join(tp, f) try: with open(fp, "r", encoding="utf-8", errors="ignore") as fh: tool_texts.append("\n".join(fh.readlines()[:300])) except Exception as e: print(f"Warning: failed to read {fp}: {e}") skill_md = os.path.join(skill_dir, "SKILL.md") if os.path.isfile(skill_md): content, _ = read_file_safe(s ...[truncated 5842 chars]- Remediation
View remediation
