T09 · Insecure Skill Coding Practices
- Location
SKILL.md:45- Finding
Predictable Temporary Archive Enables Symlink-Based File Overwrite
- Content
View full analysis
.tar.gz` as a symbolic link before the `tar` command executes. When `tar` opens the archive path for writing, it may follow the symbolic link and truncate or overwrite its target with archive data. Quoting the pathname protects against shell word splitting but does not prevent symbolic-link traversal or time-of-check/time-of-use attacks. The subsequent `rm` only removes the archive pathname and does not undo damage caused when the target was opened. ### Attack Path 1. The attacker learns or guesses the basename of a directory that the skill will share. 2. The attacker selects a target file writable by the account running the skill. 3. Before the workflow runs, the attacker creates a symbolic link such as: ```bash ln -s /path/to/writable/target /tmp/share.tar.gz ``` 4. The user or Agent runs the directory-sharing workflow with a directory named `share`. 5. `tar` opens `/tmp/share.tar.gz`, follows the attacker-controlled symbolic link, and overwrites or corrupts the target. 6. The workflow transmits the resulting archive path and then removes the temporary pathname, potentially obscuring the attack artifact without restoring the overwritten target. Successful exploitation require ...[truncated 790 chars]- Remediation
View remediation
&2 exit 1 } trap 'rm -f -- "$ARCHIVE"' EXIT tar czf "$ARCHIVE" \ -C "$(dirname -- "$DIR")" \ "$(basename -- "$DIR")" || exit 1 pilotctl --json send-file "$DEST" "$ARCHIVE" ``` Additional hardening measures: - Run the workflow as an unprivileged account and never invoke it through `sudo` unless strictly necessary. - Prefer a private temporary directory created with `mktemp -d` and restrictive permissions when multiple temporary artifacts are needed. - Check the exit status of both `tar` and `pilotctl` so failed archive creation cannot result in transmitting stale or unintended content. - Retain quoted variables and use `--` where supported to prevent pathnames beginning with a hyphen from being interpreted as command options. ]]>
