T09 · Insecure Skill Coding Practices
- Location
scripts/distill.py:999- Finding
Path Traversal Through Unsanitized Author and Account Names
- Content
View full analysis
- Remediation
View remediation
str: if not value or not SAFE_NAME.fullmatch(value): raise ValueError(f"Invalid {field}") return value ``` 2. Alternatively, generate filesystem-safe identifiers independently from display names: ```python import hashlib safe_id = hashlib.sha256(author_name.encode("utf-8")).hexdigest()[:24] ``` 3. Resolve and verify every constructed path before reading or writing: ```python def confined_path(base: Path, filename: str) -> Path: base = base.resolve() candidate = (base / filename).resolve() if not candidate.is_relative_to(base): raise ValueError("Path escapes the output directory") return candidate ``` 4. Reject values containing `/`, `\`, `..`, drive prefixes, NUL characters, or absolute paths. 5. Apply the same validation to all profile, statistics, article, cache, task, and report paths. Do not protect only the primary output file. 6. Where overwriting is unnecessary, use exclusive creation or explicit overwrite confirmation to reduce accidental data loss. ]]>
