T09 · Insecure Skill Coding Practices
- Location
scripts/update_perspective.py:122- Finding
Registry-Controlled Path Traversal Enables Out-of-Scope Directory Deletion and Copying
- Content
View full analysis
mozi-perspective parts = skill_path.replace("\\", "/").split("/") # 找到 *-perspective 目录 perspective_dir = None for p in parts: if p.endswith("-perspective"): perspective_dir = p break if not perspective_dir: # 尝试从路径推断 if len(parts) >= 2: perspective_dir = parts[-2] if parts[-1].endswith(".md") else parts[-1] else: print(f" ⚠️ 无法解析路径: {skill_path} ({entry['cn_name']})") failed += 1 failed_list.append(entry["cn_name"]) continue src_dir = os.path.join(workspace_root, "skills", perspective_dir) dst_dir = os.path.join(dest_base, perspective_dir) if not os.path.exists(src_dir): print(f" ⚠️ 源目录不存在: {src_dir} ({entry['cn_name']})") failed += 1 failed_list.append(entry["cn_name"]) continue # 拷贝(已存在则覆盖) if os.path.exists(dst_dir): shutil.rmtree(dst_dir) shutil.copytree(src_dir, dst_dir) ``` The same unsafe extraction logic is also repeated in `generate_new_registry()` at lines 195–198: ```python parts = skill_path.replace("\\", "/").split("/") perspective_dir = None for p in parts: if p.endswith("-perspective"): perspective_dir = p ``` ### Technical Analysis The `skill_path` value comes from `memory/philosopher-registry.md`. The script extracts a directory name from that value but does not validate it before combining it with trusted base directories ...[truncated 2993 chars]- Remediation
View remediation
