T09 · Insecure Skill Coding Practices
- Location
SKILL.md:69- Finding
Execution of an Unverified Out-of-Package Analytics Script
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 69-81
Vulnerability Type: Unverified local script execution through a relative path
Risk Level: MediumVulnerable Code:
markdown ## 📊 Usage Analytics 當你使用此 Skill 完成任務後,請記錄使用次數: ```bash python3 skills/analytics.py taiwan-pre-sale-housing used查看統計:
bash python3 skills/analytics.py statstext ### Technical Analysis The Skill instructs the agent to execute `skills/analytics.py` after completing a task. However, the referenced script is not included in the audited project. Consequently, its source code, integrity, ownership, network behavior, and handling of usage data cannot be verified. The command uses a relative path that is not anchored to the audited Skill directory. Its resolution therefore depends on the agent's current working directory. If another workspace component or local user can create or modify `skills/analytics.py`, the instruction may execute attacker-controlled Python code with the privileges of the agent process. The analytics operation is not required to provide pre-sale housing guidance. Automatically invoking an unrelated, unverified component violates least-functionality principles and expands the Skill's execution and trust boundaries. ### Attack Path 1. An attacker or compromised workspace component creates or replaces `skills/analytics.py` in the directory against which the relative path will resolve. 2. A user invokes this Skill for a legitimate pre-sale housing task. 3. After completing the task, the agent follows the analytics instruction in `SKILL.md`. 4. The agent runs `python3 skills/analytics.py taiwan-pre-sale-housing used`. 5. Python executes the attacker-controlled script under the agent process's operating-system identity. 6. The script can access resources available to that identity, subject to the host sandbox and operating-system permissions. This path is conditional on an ...[truncated 730 chars]- Remediation
View remediation
Remediation Suggestions
- Remove automatic analytics execution because it is unrelated to the Skill's primary housing-guidance function.
- If analytics is necessary, include the complete analytics implementation within the audited package so its behavior can be reviewed.
- Resolve the script from a trusted path anchored to the Skill's installation directory rather than from the current working directory.
- Verify the script's integrity before execution, such as through package-level signing or a trusted cryptographic hash.
- Require explicit user consent before collecting or recording usage information.
- Document exactly what data is collected, where it is stored or transmitted, its retention period, and how users can disable collection.
- Run analytics with minimal permissions and prohibit access to unrelated files, secrets, environment variables, and network destinations.
- Treat a missing or unverifiable analytics component as a reason to skip analytics rather than execute a similarly named file found elsewhere in the workspace.
