T09 · Insecure Skill Coding Practices
- Location
scripts/classer.py:75- Finding
Destination Path Traversal Allows Writes Outside the Client Archive
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This accounting archiving skill matches its stated purpose, but its file handling is too loosely bounded and could copy or write files outside the intended archive if given hostile metadata.
Install only if this skill will run on trusted dossier metadata and under a restricted account whose read/write access is limited to the intended intake and archive folders. Before production use, require safe slug/date validation, reject absolute or parent-directory paths, verify source files are inside an approved intake directory, and enforce the archive boundary before mkdir or copy operations.
scripts/classer.py:75Destination Path Traversal Allows Writes Outside the Client Archive
scripts/classer.py:141Unrestricted Source Paths Allow Unauthorized Local File Archival
No suspicious patterns detected.