T09 · Insecure Skill Coding Practices
- Location
scripts/research_investors.py:264- Finding
Path Traversal Through Unvalidated Company Name in Default Output Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent investor-research helper, but its bundled script can write reports outside the expected folder and overwrite writable files if given a crafted company name.
Before installing, treat generated investor reports as potentially sensitive fundraising material. If you run the bundled script, use an explicit safe --output path, avoid untrusted JSON input, and check for existing files because the default filename logic can overwrite writable markdown files outside the expected folder when company_name contains path components.
scripts/research_investors.py:264Path Traversal Through Unvalidated Company Name in Default Output Path
The skill instructs saving a report to the current working directory, which implies file-write capability, but it declares no explicit tool scope or permissions. Undeclared file access reduces transparency and can enable unintended reads/writes if the runtime grants broader capabilities than the user expects.
The skill mandates presenting the information-gathering questions in Chinese, but does not indicate that this is optional or based on user preference. This creates a language/locale policy issue because the skill imposes a specific language without explicit user opt-in.
The skill directs the agent to save output to a local file without clearly warning the user that a file will be created. Silent file creation can surprise users, overwrite existing work, or leave sensitive fundraising information stored on disk without explicit consent.
No suspicious patterns detected.