T09 · Insecure Skill Coding Practices
- Location
scripts/stream_processor.py:1455- Finding
Arbitrary File Overwrite Through an Unsanitized Pipeline Name
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a data-engineering generator, but one documented generator can overwrite files outside its output folder and its local Docker stack is unsafe on shared or public hosts.
Review before installing or using this skill. Only run generation commands on trusted configuration files, choose a disposable output directory, and inspect generated paths before execution. Do not start the generated Docker Compose stack on a shared, cloud, or public-facing host unless you first bind ports to localhost, add authentication, replace default credentials, and pin container image versions.
scripts/stream_processor.py:1455Arbitrary File Overwrite Through an Unsanitized Pipeline Name
scripts/stream_processor.py:1077Generated Development Stack Exposes Unauthenticated Services and Predictable Credentials
scripts/stream_processor.py:1154Generated Docker Compose Configuration Uses a Mutable Third-Party Image Tag
This variant includes a concrete security-relevant issue: the skill declares no permissions while describing behavior that writes output files. Undeclared write capability in a skill package can bypass user expectations and platform policy assumptions, especially if operators trust the metadata to determine safe execution boundaries.
This variant includes a concrete security-relevant issue: the skill declares no permissions while describing behavior that writes output files. Undeclared write capability in a skill package can bypass user expectations and platform policy assumptions, especially if operators trust the metadata to determine safe execution boundaries.
This variant includes a concrete security-relevant issue: the skill declares no permissions while describing behavior that writes output files. Undeclared write capability in a skill package can bypass user expectations and platform policy assumptions, especially if operators trust the metadata to determine safe execution boundaries.
Referenced artifact was not completely inspected
3. Generate Kafka configurations with `kafka_config_generator.py`
Referenced artifact was not completely inspected
3. Generate Kafka configurations with `kafka_config_generator.py`
Referenced artifact was not completely inspected
3. Generate Kafka configurations with `kafka_config_generator.py`
Referenced artifact was not completely inspected
3. Generate Kafka configurations with `kafka_config_generator.py`
Referenced artifact was not completely inspected
3. Generate Kafka configurations with `kafka_config_generator.py`
Referenced artifact was not completely inspected
3. Generate Kafka configurations with `kafka_config_generator.py`
Referenced artifact was not completely inspected
3. Generate Kafka configurations with `kafka_config_generator.py`
Referenced artifact was not completely inspected
**Pipeline Patterns:** See [frameworks.md](references/frameworks.md) for Lambda Architecture, Kappa Architecture, Medallion Architecture (Bronze/Silver/Gold), a
Referenced artifact was not completely inspected
**Pipeline Patterns:** See [frameworks.md](references/frameworks.md) for Lambda Architecture, Kappa Architecture, Medallion Architecture (Bronze/Silver/Gold), a
Referenced artifact was not completely inspected
**Pipeline Patterns:** See [frameworks.md](references/frameworks.md) for Lambda Architecture, Kappa Architecture, Medallion Architecture (Bronze/Silver/Gold), a
Referenced artifact was not completely inspected
**Pipeline Patterns:** See [frameworks.md](references/frameworks.md) for Lambda Architecture, Kappa Architecture, Medallion Architecture (Bronze/Silver/Gold), a
Referenced artifact was not completely inspected
**Pipeline Patterns:** See [frameworks.md](references/frameworks.md) for Lambda Architecture, Kappa Architecture, Medallion Architecture (Bronze/Silver/Gold), a
Referenced artifact was not completely inspected
**Pipeline Patterns:** See [frameworks.md](references/frameworks.md) for Lambda Architecture, Kappa Architecture, Medallion Architecture (Bronze/Silver/Gold), a
Referenced artifact was not completely inspected
**Pipeline Patterns:** See [frameworks.md](references/frameworks.md) for Lambda Architecture, Kappa Architecture, Medallion Architecture (Bronze/Silver/Gold), a
Referenced artifact was not completely inspected
**Analysis Tools:** See [tools.md](references/tools.md) for complete documentation on etl_performance_optimizer.py with query analysis and Spark tuning.
Referenced artifact was not completely inspected
**Analysis Tools:** See [tools.md](references/tools.md) for complete documentation on etl_performance_optimizer.py with query analysis and Spark tuning.
Referenced artifact was not completely inspected
**Analysis Tools:** See [tools.md](references/tools.md) for complete documentation on etl_performance_optimizer.py with query analysis and Spark tuning.
Referenced artifact was not completely inspected
**Analysis Tools:** See [tools.md](references/tools.md) for complete documentation on etl_performance_optimizer.py with query analysis and Spark tuning.
Referenced artifact was not completely inspected
**Analysis Tools:** See [tools.md](references/tools.md) for complete documentation on etl_performance_optimizer.py with query analysis and Spark tuning.
Referenced artifact was not completely inspected
**Analysis Tools:** See [tools.md](references/tools.md) for complete documentation on etl_performance_optimizer.py with query analysis and Spark tuning.
Referenced artifact was not completely inspected
**Analysis Tools:** See [tools.md](references/tools.md) for complete documentation on etl_performance_optimizer.py with query analysis and Spark tuning.
Referenced artifact was not completely inspected
**Analysis Tools:** See [tools.md](references/tools.md) for complete documentation on etl_performance_optimizer.py with query analysis and Spark tuning.
Detected: suspicious.exposed_secret_literal