T09 · Insecure Skill Coding Practices
- Location
SKILL.md:62- Finding
Arbitrary Shell Command Injection Through Crafted Filenames
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a file-sync helper, but its example overclaims safe two-way conflict handling and includes unsafe shell code that can execute commands from crafted filenames.
Review before installing or using. Only run this against a tightly controlled directory and trusted remote peer, and do not rely on it for real bidirectional sync or conflict recovery as written. The manifest-generation example should be fixed before use because malicious or unusual filenames could trigger shell command execution.
SKILL.md:62Arbitrary Shell Command Injection Through Crafted Filenames
The skill advertises bidirectional synchronization with conflict detection, but the documented implementation only performs outbound sends and passive listing of received files. This mismatch is dangerous because operators may rely on it for consistency or recovery and unknowingly lose updates, fail to propagate remote changes, or assume conflicts are handled when they are not.
The examples transmit file contents and detailed manifests, including filenames, hashes, and timestamps, to a remote peer without any warning about privacy, sensitivity, or scope. In a file synchronization skill, this context increases risk because users may point the tool at broad directories and unintentionally exfiltrate confidential data or metadata across the network.
The workflow example explicitly claims 'Bidirectional sync with conflict detection' while the script only builds a local manifest, sends it, and watches for local changes to transmit outward. Users following this example could deploy it expecting safe two-way sync and conflict handling, leading to silent divergence, overwrites by external processes, or missed remote updates.
No suspicious patterns detected.