T09 · Insecure Skill Coding Practices
- Location
scripts/translate_skill.py:98- Finding
Arbitrary Recursive Directory Deletion via Unrestricted Output Path
- Content
View full analysis
Vulnerability Details
File Location:
scripts/translate_skill.py, lines 98-99 and 440-444
Vulnerability Type: Unrestricted user-controlled path used for recursive deletion
Risk Level: HighVulnerable Code
python if output_override: target_path = Path(output_override).expanduser().resolve()python # Create the target directory if target_path.exists(): print("Target directory already exists and will be overwritten") shutil.rmtree(target_path) target_path.mkdir(parents=True)The translated English message above corresponds to the original Chinese status message; executable behavior is unchanged.
Technical Analysis
The command-line
--outputargument is converted into an absolute path but is not constrained to an approved output directory. The script does not reject critical paths, verify that the destination was previously generated by this tool, ensure that the source and target differ, or require confirmation before deletion.Calling
Path.resolve()only normalizes the supplied path; it does not establish that the path is safe. Any existing writable directory selected through--outputis passed directly toshutil.rmtree(), which recursively removes its contents.The option is part of the documented interface in
SKILL.md, which demonstrates invocation with--output /custom/output. Consequently, an accidental argument or an attacker-influenced instruction can direct the script to remove unrelated data.Attack Path
- An attacker, untrusted Skill instruction, or mistaken user command supplies an existing writable directory through
--output. get_skill_paths()resolves and accepts that directory without containment or protected-path validation.translate_skill()detects that the destination exists.- The script invokes
shutil.rmtree(target_path). - The selected directory and all descendants are recursively deleted before the re ...[truncated 848 chars]
- An attacker, untrusted Skill instruction, or mistaken user command supplies an existing writable directory through
- Remediation
View remediation
Remediation Suggestions
- Restrict output destinations to an explicitly approved base directory, such as the configured Claude Skills directory, and validate containment using resolved paths.
- Reject filesystem roots, home directories, the source directory, ancestors of the source directory, and other protected locations.
- Explicitly verify that
source_path != target_pathand that neither path contains the other where deletion could affect source data. - Do not recursively delete an existing destination by default. Abort with an error unless the user supplies an explicit
--forceoption. - When running interactively, display the resolved destination and require affirmative confirmation before destructive replacement.
- Create generated output in a new staging directory, validate it, and use a controlled rename or replacement operation only after successful processing.
- Before replacing an existing directory, require a tool-specific marker file proving that the directory was generated by this script.
- Add automated tests covering root paths, home paths, source/output equality, parent-child path relationships, symlink-resolved paths, and unrelated existing directories.
