Back to skill

Security audit

本地文件整理虾

Security checks for vulnerabilities and agentic risk

Overview

This file-organizer skill is coherent in purpose, but its file-moving behavior has under-scoped safeguards that could reorganize files unexpectedly or outside the intended target.

Review this carefully before installing. Use it only on test folders or backed-up data first, always run with --dry-run, and avoid custom rules from untrusted sources. Do not use --rules unless category names are simple folder names, and do not run it on broad locations like a home directory or project tree without a separate target directory and manual review of the planned moves.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/organize_files.py:37
Finding

Unvalidated custom category names allow destination path traversal

Content
View full analysis
str: ext = ext.lower().lstrip(".") for category, extensions in rules.items(): if ext in extensions: return category return "Others" def safe_move(src: Path, dst_dir: Path, dry_run=False) -> Path: """移动文件,自动处理命名冲突""" dst_dir.mkdir(parents=True, exist_ok=True) dst = dst_dir / src.name if dst.exists() and dst != src: stem, suffix = src.stem, src.suffix i = 1 while dst.exists(): dst = dst_dir / f"{stem}_{i}{suffix}" i += 1 if not dry_run: shutil.move(str(src), str(dst)) return dst ``` ```python for f in files: category = get_file_category(f.suffix, rules) dst_dir = target / category if f.parent == dst_dir: stats["skipped"] += 1 continue dst = safe_move(f, dst_dir, dry_run=dry_run) ``` ```python if args.rules: with open(args.rules, encoding="utf-8") as f: rules = json.load(f) ``` ### Technical Analysis Keys from a user-supplied JSON rules file become category names without validation. The program subsequently appends each category directly to the target path. A category containing parent-directory components, such as `../../outside`, causes the resulting path to escape the intended target directory. Under `pathlib`, an absolute category such as `/tmp/drop` also replaces the preceding target path entirely. The program does not reject absolute paths, directory separators, or `..` components, and it does not verify that the resolved destination remains beneath the resolved target. The resulting destination is passed to `mkdir()` and `shutil.move()`, allowing matching source files to be moved to attacker-selected loc ...[truncated 1294 chars]
Remediation
View remediation
Path: category_path = Path(category) if ( category_path.is_absolute() or category in {".", ".."} or len(category_path.parts) != 1 or "/" in category or "\\" in category ): raise ValueError(f"Invalid category name: {category!r}") resolved_target = target.resolve() destination = (resolved_target / category).resolve() if not destination.is_relative_to(resolved_target): raise ValueError("Category destination escapes the target directory") return destination ``` 3. Replace `dst_dir = target / category` with the validated destination helper. 4. Validate the complete JSON schema before organization begins. Require an object whose keys are valid category names and whose values are lists of normalized extension strings. 5. Abort before moving any files if any rule is invalid, and provide a clear error identifying the rejected category. 6. Add tests for `../outside`, `../../outside`, absolute Unix paths, Windows drive paths, backslash traversal, and valid category names. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/organize_files.py:43
Finding

Dry-run mode modifies the filesystem by creating directories

Content
View full analysis
Path: """移动文件,自动处理命名冲突""" dst_dir.mkdir(parents=True, exist_ok=True) dst = dst_dir / src.name if dst.exists() and dst != src: stem, suffix = src.stem, src.suffix i = 1 while dst.exists(): dst = dst_dir / f"{stem}_{i}{suffix}" i += 1 if not dry_run: shutil.move(str(src), str(dst)) return dst ``` ### Technical Analysis The call to `dst_dir.mkdir()` occurs before the `dry_run` condition. Consequently, invoking the tool with `--dry-run` still creates every calculated category directory. This contradicts the documented preview guarantee that dry-run mode does not actually move or modify files. It also combines with the custom-category path traversal issue: a crafted category can cause directories to be created outside the target even when a user selected dry-run specifically to inspect behavior safely. ### Attack Path 1. A user invokes the organizer with `--dry-run`, expecting no filesystem changes. 2. The source contains files assigned to one or more categories. 3. For each category, `safe_move()` executes `mkdir()` before checking `dry_run`. 4. Category directories are created despite preview mode. 5. If custom rules contain an escaped or absolute category path, directories may also be created outside the intended target. ### Impact Assessment The issue allows unintended directory creation with the privileges of the current user. It can leave filesystem artifacts, alter directory structure, and violate automation or testing assumptions that dry-run execution is side-effect free. On its own, this issue does not move file contents or elevate privileges. Its impact is limited to creating directories in locations writable by ...[truncated 132 chars]
Remediation
View remediation
Path: dst = dst_dir / src.name if dst.exists() and dst != src: stem, suffix = src.stem, src.suffix i = 1 while dst.exists(): dst = dst_dir / f"{stem}_{i}{suffix}" i += 1 if not dry_run: dst_dir.mkdir(parents=True, exist_ok=True) shutil.move(str(src), str(dst)) return dst ``` Additionally: 1. Apply destination containment validation before both preview and execution. 2. Ensure dry-run mode performs no writes, directory creation, permission changes, timestamp updates, or report generation. 3. Add automated tests that snapshot the source and target directory trees before and after dry-run execution and assert that they are identical. 4. Clearly separate planning from execution: first calculate an immutable move plan, then apply it only when dry-run mode is disabled. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description overclaims capabilities such as duplicate cleanup and batch renaming that are not actually implemented as described. This can mislead the agent or user into authorizing riskier file operations under false assumptions, reducing informed consent and increasing the chance of unintended data handling.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises file-organizing behavior that necessarily writes to the filesystem, but it does not declare any explicit tool scope or permissions boundary in the skill manifest. That creates an authorization and review gap: an agent may invoke file-writing behavior without clear user-visible constraints on what paths or operations are allowed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill name and description are written in Chinese, but there is no indication that the skill is region-specific or that users may choose their preferred language. This can violate language or locale policy when a skill implicitly constrains interaction language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation examples include broad phrases such as "整理文件", "文件管理", and "文件夹整理", which are common everyday requests and may overlap with many unrelated file-assistance tasks. The description does not provide exclusion conditions or negative examples to clarify when this skill should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation defines automatic duplicate-handling and a retention policy that can delete or retain files based on heuristics such as modification time, naming quality, resolution, or shortest path, but it does not clearly warn that these rules can preserve the wrong file. In a local file organizer skill, users are likely to rely on this guidance for destructive actions, so insufficient warning materially increases the risk of unintended data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language strings in the module docstring and user-facing interface are written in Chinese, which imposes a specific language/locale on users without any visible opt-in or documented regional constraint. Under the policy, locale or language restrictions should either be optional for the user or clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script defaults target to the source directory and then immediately performs file moves across the tree, which changes the user's original directory layout without an explicit confirmation or safety gate. In a local file-organizer skill, destructive or hard-to-reverse file operations are especially risky because a user may expect analysis or preview behavior first, and accidental reorganization can disrupt workflows or software projects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.