T09 · Insecure Skill Coding Practices
- Location
SKILL.md:21- Finding
Predictable Temporary Files Allow File Clobbering and Capture Collisions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 21–29
Vulnerability Type: Predictable temporary files with forced overwrite
Risk Level: MediumEvidence
bash ffmpeg -loglevel error -f avfoundation -framerate 30 -i "0" -t 5 -y /tmp/brio_warmup.mp4 && \ ffmpeg -loglevel error -sseof -0.5 -i /tmp/brio_warmup.mp4 -frames:v 1 -update 1 -y /tmp/brio.jpgbash ffmpeg -loglevel error -f avfoundation -pixel_format nv12 -framerate 30 -i "1" -t 5 -y /tmp/facetime_warmup.mp4 && \ ffmpeg -loglevel error -sseof -0.5 -i /tmp/facetime_warmup.mp4 -frames:v 1 -update 1 -y /tmp/facetime.jpgTechnical Analysis
The capture commands use fixed, globally predictable paths under
/tmpand instructffmpegto overwrite existing destinations with-y. The commands do not create a private temporary directory, verify file ownership, reject symbolic links, or generate unique filenames.Concurrent skill invocations can overwrite or mix one another's files. A local attacker able to create entries at the predictable paths before invocation may also attempt a symbolic-link or path-prepositioning attack. If the output-opening behavior follows an attacker-controlled link, a file writable by the skill's operating-system account could be truncated or replaced. The attack remains limited by the privileges of the account running
ffmpeg; the commands do not independently provide privilege escalation.Attack Path
- A local attacker predicts one of the documented paths, such as
/tmp/brio.jpgor/tmp/brio_warmup.mp4. - Before the skill runs, the attacker creates a conflicting filesystem entry or symbolic link at that path.
- A user invokes the camera skill.
ffmpeg -yopens the predictable destination without validating that it is a newly created regular file owned by the invoking account.- Depending on filesystem and
ffmpegbehavior, the destination may be overwritten, redir ...[truncated 580 chars]
- A local attacker predicts one of the documented paths, such as
- Remediation
View remediation
Remediation Suggestions
- Create a unique private working directory with
mktemp -dfor every invocation. - Set restrictive permissions with
umask 077and directory mode0700. - Place both intermediate videos and final images inside that private directory.
- Avoid blindly overwriting existing paths. Ensure output files do not already exist and are regular files owned by the invoking account.
- Where possible, use APIs or file-opening controls that reject symbolic links, such as
O_NOFOLLOWsemantics. - Serialize access to each physical camera or use invocation-specific filenames to prevent concurrent-run collisions.
- Install a shell trap that reliably removes all temporary artifacts on success, failure, or interruption.
- Move or copy the final image to a caller-approved destination only after capture and validation.
- Create a unique private working directory with
