T09 · Insecure Skill Coding Practices
- Location
spec_tools.py:142- Finding
Arbitrary File Overwrite Through Specification Path Traversal
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed project helper, but its broad automatic activation and under-scoped file-writing tool need review before installation.
Install only if you are comfortable with a globally enabled project assistant that can auto-activate on broad development wording. Keep it project-scoped if possible, disable autoInvoke unless needed, and do not pass untrusted values to spec_tools.py until path containment is fixed.
spec_tools.py:142Arbitrary File Overwrite Through Specification Path Traversal
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
brew install python@3.11
### Q4: How to update skill?
**A**: Re-run installation script:
```bash
The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.
The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.
The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.
The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.
The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.
The English-language finding similarly shows a trust-breaking mismatch: manual single-agent invocation and basic JSON status tracking are presented as automatic routing, collaboration, consensus, lifecycle management, and bilingual support. Even absent overtly dangerous code, deceptive or inaccurate claims can cause over-trust, misconfiguration, and approval of broader capabilities than intended.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
| 环境 | 服务器 | 数据库 | 配置文件 |
|------|--------|--------|----------|
| 开发环境 | 本地服务器 | 本地数据库 | .env.local |
| 测试环境 | 测试服务器 | 测试数据库 | .env.test |
| 生产环境 | 生产服务器 | 生产数据库 | .env.production |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
|------|--------|--------|----------|
| 开发环境 | 本地服务器 | 本地数据库 | .env.local |
| 测试环境 | 测试服务器 | 测试数据库 | .env.test |
| 生产环境 | 生产服务器 | 生产数据库 | .env.production |
### 6.2 部署流程
The example explicitly states that files are modified, added, deleted, and even '代码已提交' without showing any user approval gate, dry-run, or confirmation step. In an agent skill focused on autonomous multi-step execution, normalizing silent destructive changes can lead users to enable workflows that overwrite or remove project assets unexpectedly.
该贡献指南在“中文注释规范”部分明确要求“使用中文注释”,属于对贡献者输出语言的强制性约束。文件未说明这是可选项、未提供其他语言选项,也未给出明确的区域合规或项目范围理由,符合语言/locale policy violation 的判定条件。
Forcing output to the first detected language in mixed-language inputs can misinterpret user intent and be abused to steer the agent into an unintended language context. While not a direct code-execution flaw, it can degrade safety controls, user comprehension, and review accuracy in bilingual workflows where exact wording matters.
The Architect trigger list includes broad phrases like code review, security check, and performance optimization that commonly appear in normal developer requests. Without explicit routing constraints or confirmation, the system may invoke a higher-privilege or differently-scoped role than the user intended, causing prompt-scope confusion and unintended authority transfer across agents.
The Product Manager trigger keywords are generic requirement-related phrases that can appear in ordinary planning or implementation conversations. This can cause unintended invocation of the PM role, leading to incorrect workflow execution, prompt injection surface expansion across roles, and misalignment between user intent and agent behavior.
The Test Expert activation phrases are broad enough to match routine development requests, especially terms like test plan, unit testing, and quality review. Ambiguous routing can shift execution into a testing-oriented prompt unexpectedly, which is dangerous in a multi-agent system because it alters tool use, priorities, and output constraints without clear user authorization.
The Solo Coder triggers are everyday development phrases such as implement feature, fix bug, and write code, so they are highly likely to over-match. In a multi-agent skill, this can silently route many requests into code-writing behavior, increasing the risk of unauthorized code changes, bypass of review-oriented roles, and confusion over expected safeguards.
This markdown file presents all user-facing instructions, examples, and help text only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.
The examples introduce standalone tooling for spec management, codebase scanning, code-map generation, and project-understanding outputs that exceed the declared purpose of multi-agent task dispatch. This scope expansion can mislead users and downstream agents into invoking undocumented capabilities over local repositories, increasing the risk of unintended file access, data exposure, or over-privileged behavior without clear manifest disclosure or security review.
The example PRD includes 'User operation behavior' under tracking requirements without any accompanying privacy notice, consent requirement, data minimization guidance, or retention limits. In a skill that users may copy directly into product specifications, this normalizes behavior tracking as a default practice and can lead downstream implementations to collect telemetry in ways that violate privacy expectations or regulatory requirements.
The examples use broad free-form prompts like architecture design, product definition, testing, and implementation requests that are similar to normal chat requests. In combination with automatic task recognition, this can cause the skill to activate on ambiguous user input and steer the session into high-authority workflows unexpectedly.
The documented installation copies the skill into ~/.trae/skills/trae-multi-agent/, creating a persistent user-level artifact that remains active across sessions. In the context of a skill that can auto-invoke and orchestrate multiple roles, persistent installation increases the blast radius of accidental or unsafe behavior because the capability survives beyond a single project or session.
# 1. 创建技能目录
mkdir -p ~/.trae/skills/trae-multi-agent
# 2. 复制技能文件
cp -r /path/to/claw/.trae/skills/trae-multi-agent/* \
The README explicitly documents a configuration with autoInvoke: true but does not describe narrow activation boundaries, approval gates, or trigger restrictions. For a multi-agent skill that can route broad natural-language prompts into role prompts and scripts, unconstrained auto-invocation increases the chance of unintended activation during ordinary conversation, amplifying prompt-injection and overreach risk.
The README states the skill can be used directly and elsewhere describes automatic task identification and dispatching, but does not define strict activation boundaries. In an agentic environment, broad or implicit auto-activation can cause the skill to engage on unintended prompts, increasing the chance of inappropriate role switching, overreach, or execution of workflows on sensitive tasks.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
### 4. Solo Coder / 独立开发者
**Responsibilities**: Write complete, high-quality, maintainable, and testable code
**Core Principles**:
- ✅ Zero Tolerance Checklist - 10 absolute prohibitions
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
~/.trae/skills/trae-multi-agent/
ls -lh ~/.trae/skills/trae-multi-agent/SKILL.md
No suspicious patterns detected.