T09 · Insecure Skill Coding Practices
- Location
scripts/uninstall.sh:6- Finding
Unrestricted Environment Variable Enables Arbitrary Recursive Directory Deletion
- Content
View full analysis
Vulnerability Details
File Location:
scripts/uninstall.sh:6-10
Vulnerability Type: Unsafe recursive deletion using an unvalidated, user-controlled path
Risk Level: HighVulnerable Code
bash WATCHLIST_DIR="${STOCK_WATCHER_DATA_DIR:-$SKILL_DIR/data}" WATCHLIST_DIR="${WATCHLIST_DIR/#\~/$HOME}" if [ -d "$WATCHLIST_DIR" ]; then rm -rf "$WATCHLIST_DIR" fiTechnical Analysis
The
STOCK_WATCHER_DATA_DIRenvironment variable directly determines the target passed torm -rf. Although quoting prevents shell-word splitting and command injection, the script does not canonicalize the path, restrict it to a dedicated application directory, verify an ownership marker, or reject dangerous targets such as/,$HOME, or unrelated directories.Supporting a custom data location is consistent with the Skill's declared functionality, but recursively deleting the entire configured directory exceeds the minimum privilege needed to remove the watchlist. The script only needs to remove the Skill-owned
watchlist.txtfile and, at most, remove the containing directory if it is known to have been created exclusively by this Skill and is empty.Attack Path
- An attacker, automation wrapper, or unsafe execution environment controls
STOCK_WATCHER_DATA_DIR. - The variable is set to an existing valuable directory, for example:
bash STOCK_WATCHER_DATA_DIR="$HOME" bash scripts/uninstall.sh - The script confirms only that the selected path is a directory.
rm -rf "$WATCHLIST_DIR"recursively deletes that directory and all accessible contents.- If the script is run with elevated privileges, the deletion scope expands to files accessible to that privileged account.
Impact Assessment
Exploitation can destroy arbitrary directories writable by the account running the script. Under a normal user account, this could include personal files, configuration, credentials, and ...[truncated 302 chars]
- An attacker, automation wrapper, or unsafe execution environment controls
- Remediation
View remediation
Remediation Suggestions
- Remove only the specific Skill-owned file:
bash WATCHLIST_FILE="$WATCHLIST_DIR/watchlist.txt" rm -f -- "$WATCHLIST_FILE" rmdir -- "$WATCHLIST_DIR" 2>/dev/null || true - Canonicalize and validate the directory before any destructive operation.
- Explicitly reject empty paths,
/,$HOME, the project root, and other protected locations. - Place a unique ownership marker in directories created by the Skill and require that marker before deleting the directory.
- Never recursively delete a custom directory merely because it was supplied through an environment variable.
- Require explicit user confirmation before removing non-default data locations.
- Do not recommend or require elevated privileges for uninstallation.
- Remove only the specific Skill-owned file:
