T09 · Insecure Skill Coding Practices
- Location
SKILL.md:30- Finding
Predictable Shared Temporary Path Enables Symlink and File-Replacement Attacks
- Content
View full analysis
/tmp/trading-devbox/strategy.py << 'PYEOF' import backtrader as bt import sys import json class UserStrategy(bt.Strategy): params = dict( entry_drop_pct=10, take_profit_pct=30, stop_loss_pct=5, ) def __init__(self): self.order = None self.buy_price = None def next(self): if self.order: return if not self.position: # entry: price dropped by entry_drop_pct from recent high high = max(self.data.close.get(size=20) or [self.data.close[0]]) drop = (high - self.data.close[0]) / high * 100 if drop >= self.p.entry_drop_pct: self.order = self.buy() self.buy_price = self.data.close[0] else: pnl = (self.data.close[0] - self.buy_price) / self.buy_price * 100 if pnl >= self.p.take_profit_pct or pnl <= -self.p.stop_loss_pct: self.order = self.sell() if __name__ == '__main__': print(json.dumps({"status": "ok", "message": "Strategy generated"})) PYEOF python3 /tmp/trading-devbox/strategy.py ``` ### Technical Analysis The workflow creates and executes Python code through the fixed, globally predictable path `/tmp/trading-devbox/strategy.py`. The command `mkdir -p` does not verify that an existing path is owned by the invoking user, is a real directory rather than an indirect path, or has secure permissions. If another local user pre-creates `/tmp/trading-devbox`, the command accepts that directory without error. Shell output redirection follows symbolic links, so an attacker-controlled `strategy.py` symlink could cause the generated content to truncate and overwrite another file that the invoking account ...[truncated 2198 chars]- Remediation
View remediation
"$strategy_file" <<'PYEOF' # Generated strategy code PYEOF python3 -- "$strategy_file" ``` 2. Do not reuse a fixed directory under `/tmp`. `mktemp -d` atomically creates an unpredictable directory and prevents another user from pre-creating the same path. 3. Apply `umask 077` so generated directories and files are accessible only to the invoking account. 4. Quote all path variables and use `--` where supported to prevent path parsing errors. 5. Keep the generated file inside the newly created private directory and delete the directory through a cleanup trap. 6. For higher-assurance implementations, create files using APIs that support exclusive creation and no-follow semantics, such as `O_CREAT | O_EXCL | O_NOFOLLOW`, and execute only after verifying ownership, file type, and permissions. 7. If generated strategy code may contain untrusted user-derived logic, execute it in an isolated container or sandbox with: - No host credentials or sensitive environment variables. - A read-only filesystem except for a dedicated work directory. - No network access unless explicitly required. - CPU, memory, process, and execution-time limits. - A non-privileged user and no additional Linux capabilities. ]]>
