T09 · Insecure Skill Coding Practices
- Location
SKILL.md:64- Finding
Predictable and Potentially World-Readable Temporary Event Recording
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 64–68
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Mediumbash RECORDING="/tmp/debug-session-$(date +%Y%m%d-%H%M%S).ndjson" pilotctl --json subscribe "$SOURCE" "*" --timeout "$DURATION" | \ jq -c '.data.events[]' >> "$RECORDING"Technical Analysis
The recording filename is generated predictably using a timestamp with one-second precision and placed directly in the shared
/tmpdirectory. The shell's append redirection opens the path without atomically ensuring that it is a newly created regular file. If the path already exists as a symbolic link, the redirection follows that link.The workflow also does not set a restrictive
umaskor explicitly restrict file permissions. Under a common022umask, a newly created recording can have mode0644, allowing other local users to read it. Because the subscription uses the wildcard topic"*", the file may contain a broad range of sensitive operational event data.Attack Path
- A local attacker determines when the recording workflow is likely to run.
- The attacker predicts the timestamp-derived pathname under
/tmp. - Before redirection occurs, the attacker creates that pathname as a symbolic link to a target file that the workflow's user can write.
- The user runs the documented workflow.
- The shell follows the symbolic link and appends captured events to the linked target.
- Independently, if a normal recording is created with a permissive default umask, another local user can open the resulting file and read captured events.
Exploitation requires local access and sufficient ability to create entries in the shared temporary directory. Symlink exploitation is further limited to destination files writable by the victim process; this workflow does not itself grant elevated privileges.
Impact Assessment
The primary impact is local confidentiality lo ...[truncated 533 chars]
- Remediation
View remediation
Remediation Suggestions
Create the recording atomically with restrictive permissions rather than constructing a predictable pathname:
bash umask 077 RECORDING=$(mktemp "${TMPDIR:-/tmp}/debug-session.XXXXXX.ndjson") || exit 1 pilotctl --json subscribe "$SOURCE" "*" --timeout "$DURATION" | \ jq -c '.data.events[]' >> "$RECORDING"For durable recordings, create and use a user-owned directory with mode
0700outside shared/tmp, and create recording files with mode0600. Validate that the destination is a regular file, avoid following symbolic links where platform APIs permit, apply an appropriate retention and secure-deletion policy, and warn users that wildcard subscriptions may capture sensitive data.
