Back to skill

Security audit

proj-builder

Security checks for vulnerabilities and agentic risk

Overview

This scaffold generator appears purpose-aligned, but its init command can overwrite files in any writable path the user or agent supplies without a clear preflight warning or confirmation.

Review the destination before running init. Use a fresh project directory, avoid absolute or parent-directory paths, and do not run it against an existing project unless you are comfortable with template files such as README.md, package.json, go.mod, or .gitignore being replaced.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:41
Finding

Unrestricted Scaffold Destination Permits Arbitrary File Overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 41 and 54–56; repeated at lines 73 and 81–83, 97 and 108–110, 125 and 135–137, 149 and 158–160, and 172 and 181–183
Vulnerability Type: Unvalidated filesystem path and unsafe file overwrite
Risk Level: Medium

Vulnerable Code

Each scaffold implementation derives its destination directly from the user-controlled project name:

python
name = sys.argv[1]
base = name

It then creates directories and opens every generated file in truncating write mode:

python
for path, content in files.items():
    full = os.path.join(base, path)
    os.makedirs(os.path.dirname(full), exist_ok=True)
    with open(full, 'w') as f:
        f.write(content)
    created.append(full)
    print(f"  \033[0;32m✅\033[0m {full}")

Equivalent write loops are present in all six scaffold functions.

Technical Analysis

The init command accepts the project name from a command-line argument and uses it directly as the base filesystem path. It does not reject absolute paths, normalize and constrain the destination to an approved workspace, detect path traversal, check for symbolic links, or require confirmation before modifying an existing destination.

Python's open(full, 'w') truncates an existing file before writing. Consequently, selecting an existing directory can silently replace files whose relative names match the selected template, such as README.md, .gitignore, package.json, go.mod, or main.go. Filesystem operations may also follow symbolic links.

This behavior is not necessary for the minimum functionality of generating a new scaffold. A scaffold generator can instead require a new destination under a designated workspace and refuse existing files by default.

The static pre-scan warning concerning executable retrieval is a false positive. Lines 175–176 contain strings that generate ordinary Go source files. The audited imp ...[truncated 1459 chars]

Remediation
View remediation

Remediation Suggestions

  1. Reject absolute project paths and project names containing .., path separators, NUL characters, or platform-specific path escape forms.
  2. Resolve the requested destination with pathlib.Path.resolve() and verify that it remains beneath an explicitly approved workspace directory.
  3. Require the destination directory to be absent or empty by default. Abort if it already exists unless the user supplies an explicit --force option.
  4. Use exclusive file creation, such as Python mode x or os.open() with O_CREAT | O_EXCL, to prevent accidental truncation.
  5. Detect and reject symbolic links in the destination path and generated file targets. Where supported, use no-follow filesystem options.
  6. Before any forced overwrite, display the resolved destination and exact files that will be replaced, then require explicit confirmation.
  7. Apply the same centralized destination-validation routine to all six scaffold functions to prevent inconsistent protections.
  8. Add tests covering absolute paths, ../ traversal, existing destinations, existing files, and symbolic-link targets.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script's init flow creates directories and writes many files under a user-supplied project name via the scaffold_* functions, which is a safety-relevant filesystem modification. Although individual created files are printed after the fact, there is no prior warning or confirmation that running init will perform bulk file creation in the target path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.