T09 · Insecure Skill Coding Practices
- Location
audit.sh:25- Finding
Unsanitized Task ID Enables Path Traversal and Unauthorized File Writes
- Content
View full analysis
"$report_file" << EOF # 🔍 任务审计报告 **任务 ID**: $task_id **审计时间**: $(date "+%Y-%m-%d %H:%M:%S") **质量评分**: $score/100 ``` ### Technical Analysis The script accepts `TASK_ID` directly from its first command-line argument: ```bash TASK_ID="$1" ``` This value is interpolated into log, source-report, and generated audit-report paths without validation or canonical containment checks. Shell quoting prevents shell metacharacters from causing direct command injection, but it does not prevent filesystem traversal through components such as `../`. Consequently, an attacker who can invoke the script can cause path resolution to escape the intended `completed`, `reports`, or `audits` directories. The `mkdir -p` operation can create attacker-selected directory structures, while the subsequent shell redirection can overwrite a writable file outside the expected audit directory. The destination is constrained to a name ending in `.audit.md`, unless an existing symbolic link at that destination redirects the write elsewhere. The source log and report paths are similarly affected. Their fixed suffixes limit arbitrary file selection, but an attacker can still target matching files outside the intended directories and infer information from the resulting quality score, issue list, and pass/ ...[truncated 1823 chars]- Remediation
View remediation
&2 exit 1 fi ``` 2. **Canonicalize and verify every constructed path** Resolve each path and ensure it remains beneath its expected base directory before reading or writing: ```bash AUDITS_DIR="${TASKS_DIR}/audits" mkdir -p -- "$AUDITS_DIR" audit_base=$(realpath -m -- "$AUDITS_DIR") report_file=$(realpath -m -- "${AUDITS_DIR}/${TASK_ID}.audit.md") case "$report_file" in "$audit_base"/*) ;; *) echo "Resolved audit path escapes the audit directory" >&2 exit 1 ;; esac ``` Apply equivalent containment checks to the `completed` and `reports` read paths. 3. **Defend against symbolic-link writes** Refuse output paths that are symbolic links and use a secure creation method that does not follow links. Where supported, use a small helper that opens the destination with `O_NOFOLLOW`, or write to a securely created temporary file within the validated audit directory and atomically rename it after verifying the destination. 4. **Apply restrictive permissions** Set a restrictive umask before creating reports or directories: ```bash umask 077 ``` 5. **Avoid running with unnecessary privileges** Execute the auditor under a dedicated account that can read only the required task artifacts and write only to the audit and alert directories. 6. **Add security regression tests** Tests should verify rejection of: - `../` traversal sequences. - Absolute paths. - Forward and backward path separators. - Empty or dot-only identifiers. - Symbolic-link output targets. - Identifiers that resolve outside each configured base directory. ]]>
