T09 · Insecure Skill Coding Practices
- Location
scripts/ingest.sh:31- Finding
Arbitrary Python Code Execution Through Unsafely Interpolated Paths
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent local document knowledge base, but its ingestion script has a real code-execution risk and it retains private document text and source paths without strong controls.
Review this skill carefully before installing. Only ingest PDFs and folders you trust, avoid sensitive documents unless you can protect and delete the KB_ROOT directory, set KB_ROOT to a private location with restrictive permissions, and do not run the ingestion script on files or paths supplied by untrusted parties until the Python interpolation and JSON/search handling are fixed.
scripts/ingest.sh:31Arbitrary Python Code Execution Through Unsafely Interpolated Paths
scripts/ingest.sh:46Metadata JSON Injection Through Unescaped Filename and Path Values
scripts/search.sh:28Search Query Interpreted as Grep Options and Regular Expressions
scripts/summarize.sh:29Summary Concept Interpreted as Grep Options and Regular Expressions
scripts/ingest.sh:6Private Knowledge-Base Files May Be Created with Permissive Filesystem Modes
The skill instructs users to ingest PDFs and other documents into a persistent local knowledge base, but it does not warn that personal files, extracted text, metadata, and derived embeddings will be stored for later retrieval. This creates a privacy and consent issue because users may provide sensitive documents without understanding that the content will be retained and indexed beyond the immediate session.
The skill explicitly describes persistent storage in kb/index.json and kb/docs/, along with extracted metadata and embeddings, which means user-provided document contents survive beyond the current interaction. In a personal knowledge-base context this persistence is expected functionality, but it still introduces security and privacy risk if users are not clearly informed or if sensitive documents are ingested without retention controls.
When user provides new PDFs or papers:
1. Create document entry in `kb/index.json`
2. Extract text and metadata
3. Generate embeddings for semantic search
4. Store in `kb/docs/` with normalized name
The file comment at L02 presents the script as a straightforward PDF ingestion utility, but the implementation also records the caller-supplied source path into a JSON metadata file at L50. This is not merely omitted detail about extraction; it changes the retained data footprint of the operation beyond just ingesting document contents.
No suspicious patterns detected.