T09 · Insecure Skill Coding Practices
- Location
SKILL.md:55- Finding
Unbounded Decompression of Untrusted Network Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 55-56 and 102-103
Vulnerability Type: Unrestricted decompression of remotely supplied data
Risk Level: MediumComplete Code Snippet
Lines 55-56:
bash COMPRESSED_DATA=$(echo "$INBOX" | jq -r '.items[0].content') echo "$COMPRESSED_DATA" | base64 -d | gunzipLines 102-103:
bash INBOX=$(pilotctl --json inbox) echo "$INBOX" | jq -r '.items[0].content' | base64 -d | gunzip > report.jsonTechnical Analysis
The documented receiver workflow extracts the first inbox item's content and immediately passes it through Base64 decoding and gzip decompression. It does not authenticate or authorize the sender, verify the expected compression format, validate the encoded input, limit the compressed input size, restrict the decompressed output size, or impose CPU and execution-time limits.
Compression formats can encode extremely large outputs in relatively small payloads. A malicious peer could therefore submit a gzip bomb that consumes substantial CPU, memory, or disk space when the workflow is followed. The variant redirected to
report.jsonis particularly exposed to filesystem exhaustion because decompressed data is written without an output-size limit.Attack Path
- An attacker able to send a Pilot Protocol message to the recipient constructs a small gzip payload with a very high expansion ratio.
- The attacker Base64-encodes the payload and places it in the message content.
- The recipient runs the documented inbox workflow.
jqselects the attacker's content without sender or message validation.base64 -ddecodes the payload andgunzipexpands it without resource limits.- The process consumes excessive CPU, memory, or disk capacity, potentially disrupting the agent or host.
Impact Assessment
Successful exploitation does not directly grant additional system privileges. Its primary impact is denial ...[truncated 355 chars]
- Remediation
View remediation
Remediation Suggestions
- Authenticate the sender and verify that the selected inbox item comes from an authorized peer.
- Validate message metadata, expected encoding, compression format, and compressed input size before processing.
- Use strict Base64 decoding and stop processing when decoding or format validation fails.
- Enforce a maximum decompressed size rather than piping unbounded output directly to a file.
- Run decompression with operating-system resource limits for CPU time, memory, output file size, and execution duration.
- Decompress into a private temporary directory on a filesystem with an appropriate quota.
- Inspect gzip metadata where available, but do not rely on metadata alone because declared sizes can be absent or misleading.
- Write to a temporary file, verify its final size and content type, and only then move it to the intended destination.
