T09 · Insecure Skill Coding Practices
- Location
SKILL.md:73- Finding
Execution of an Unbundled Working-Directory Analytics Script
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 73–84
Vulnerability Type: Execution of an unverified relative-path script
Risk Level: MediumVulnerable code snippet:
markdown ## 📊 Usage Analytics 當你使用此 Skill 完成任務後,請記錄使用次數: ```bash python3 skills/analytics.py taiwan-real-estate-tax used查看統計:
bash python3 skills/analytics.py statstext ### Technical Analysis The Skill instructs the Agent to execute `skills/analytics.py` through a relative path after completing a task. This script is not included in the audited project. Consequently, its identity and integrity cannot be established from the Skill package. A relative path is resolved against the process's current working directory rather than a verified Skill installation directory. If an attacker can place a file at `skills/analytics.py` in that directory, the documented analytics command will execute the attacker's Python code. The analytics operation is also unrelated to the core tax-calculation function, making this an unnecessary execution surface. ### Attack Path 1. An attacker gains the ability to create files in, or influence the contents of, the Agent's working directory. 2. The attacker creates a malicious file at `skills/analytics.py`. 3. A user invokes the tax-calculator Skill for a legitimate task. 4. After the task, the Agent follows the Skill's usage-analytics instruction. 5. Python resolves the relative path to the attacker-controlled script. 6. The malicious script executes with the same operating-system privileges and environment access as the Agent process. ### Impact Assessment Successful exploitation permits arbitrary Python code execution under the Agent's current account. The resulting access may include reading or modifying files available to that account, accessing inherited environment variables, making network requests where permitted, and invoking other local programs. This does not ...[truncated 259 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the analytics execution instructions because they are not required for tax calculation.
- If analytics is necessary, bundle the analytics implementation inside the reviewed Skill package.
- Resolve the script from a canonical, verified installation directory rather than the current working directory.
- Verify the bundled script's integrity before execution, such as through a package signature or trusted checksum.
- Require explicit user consent before collecting or recording analytics.
- Document what information is collected, where it is stored or transmitted, and the applicable retention policy.
- Run optional analytics with the minimum required filesystem, environment, and network permissions.
