T09 · Insecure Skill Coding Practices
- Location
scripts/rooms.py:9- Finding
Path Traversal Enables Filesystem Access Outside the Chat Namespace
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent file-based chat tool, but it needs Review because callers can claim other users and unvalidated paths can read, write, or delete outside the intended chat directory.
Install only in a trusted shared directory where all participants already have equivalent access and trust each other. Do not use it for private or adversarial multi-user chat until it validates path components, confines all file operations to the chat namespace, authenticates callers, enforces room membership, and adds confirmation for destructive actions.
scripts/rooms.py:9Path Traversal Enables Filesystem Access Outside the Chat Namespace
scripts/common.py:93Caller-Supplied Usernames Permit Identity Impersonation and Unauthorized Operations
scripts/send.py:59Room Membership Is Not Enforced for Reading or Sending Messages
The supplied code does not perform message sending, receiving, group/broadcast handling, or history queries. Instead, it manages user accounts and metadata stored in the shared directory. While this may be related to a broader chat system, the declared description for the skill focuses on messaging capabilities and does not mention registration/profile lifecycle operations. That makes this code chunk materially different from the declared purpose for this specific evaluation.
Without declared permissions the skill's intent is opaque and cannot be validated.
This markdown file documents operations that can remove user or room state, but it does not include any warning about data loss, reversibility, or the need for confirmation. Under the markdown criteria for missing user warnings, destructive behaviors affecting user data or system state should be disclosed.
The documentation presents room deletion as a normal action but gives no user-facing warning about its destructive effect on shared collaboration state. Markdown documentation should warn users when actions can affect system integrity or shared data.
The inline/commented intent at L42 says messages are marked as read by renaming files to '.json.read', but the unread check at L35 uses f.suffix == ".read". For files named name.json.read, pathlib.Path.suffix returns '.read', so this code sets is_read true for read files; however the inbox scan at L27 only loads *.json, meaning renamed read files are excluded entirely and this unread/read status check is not aligned with the documented mechanism.
The unregister path performs a file deletion via profile_path.unlink() to remove the user's profile. Although there is a comment noting that the inbox is preserved, there is no confirmation prompt, explicit user-facing warning, or other disclosure around the irreversible profile deletion in this code path.
The delete action invokes shutil.rmtree to remove the entire room directory, which is a destructive and irreversible operation. Although authorization is checked, this file provides no confirmation prompt, warning message, or other user disclosure before performing the deletion.
The file-level docstring and user-facing strings are written in Chinese, indicating the skill is designed around a fixed language/locale. There is no indication that users can opt into another language or that the Chinese-only behavior is a documented, justified regional constraint.
This code performs a bulk file-write operation across all registered users by iterating over every user and saving a message copy into each inbox. Although the inline comment says it broadcasts to all users, there is no confirmation prompt, explicit cautionary log, or other user disclosure around this potentially wide-impact action.
The top-level docstring is entirely in Chinese and presents the module description in a single fixed language. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint can be a natural-language policy violation.
The file contains user-facing descriptions and error messages in Chinese, such as the module docstring and parameter errors, with no indication that the user can choose another language or that the skill is intentionally region-specific. This can violate a language/locale policy when a skill implicitly forces one language for interaction.
The file-level docstring uses Chinese-only natural language (接收新消息) with no indication that language is configurable or chosen by the user. Under the stated policy, language-specific behavior or presentation should not be forced without opt-in unless clearly justified.
This Python file performs a state-changing file operation by renaming message files to mark them as read. Although the behavior is implied by the parameter name and inline comment, there is no user-facing print/log statement, confirmation prompt, or broader disclosure in this file about modifying mailbox state.
The docstring, comments, and user-visible error messages are written in Chinese, which effectively fixes the skill's interaction language without any opt-in or language-selection mechanism. Under the stated policy, locale or language constraints should either be optional for the user or clearly justified and documented.
The file's docstrings, error messages, and output text are written in Chinese throughout, which imposes a specific language on users. There is no indication of user opt-in, configurable locale selection, or justification that this skill is intentionally limited to a Chinese-language environment.
The module docstring states this script sends messages for 'single chat/group chat' only, but the implementation also supports a 'broadcast' mode at L079-L100. This is a semantic mismatch between the file-level documentation and actual behavior, though it remains within the broader skill manifest's overall messaging scope.
No suspicious patterns detected.