T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
Unauthenticated Network Exposure of the Desktop Directory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20-23 and 67-70
Vulnerability Type: Unrestricted local file serving and excessive directory exposure
Risk Level: MediumVulnerable Code
bash cd ~/Desktop python3 -m http.server 9999The same unsafe operation is repeated in the quick command:
bash # Start the server cd ~/Desktop && python3 -m http.server 9999 # Stop the server pkill -f "python3 -m http.server 9999"Technical Analysis
The instructions start Python's basic HTTP server with the entire
~/Desktopdirectory as its document root. By default,python3 -m http.server 9999listens on all available network interfaces rather than restricting access to the loopback interface.Python's basic HTTP server does not provide authentication or authorization. It can also generate directory listings when an index file is absent. Consequently, any host capable of reaching port
9999may enumerate and download readable files stored on the Desktop, including files unrelated to the generated poster.Serving the entire Desktop violates least-exposure principles because the workflow only requires access to one generated HTML file from a browser running on the same machine. The exposure may last longer than intended if the user omits cleanup, the agent is interrupted, or the broad
pkillcommand fails to identify the relevant process.Attack Path
- The agent creates a poster file under
~/Desktop. - The agent changes the working directory to
~/Desktop. - It runs
python3 -m http.server 9999, which listens on reachable interfaces and exposes the current directory without authentication. - An attacker on the same network, or another system with access to the host and port, connects to
http://<target-host>:9999/. - The server returns a directory listing if no index file suppresses it.
- The attacker identifies and requests unrelated Desktop ...[truncated 793 chars]
- The agent creates a poster file under
- Remediation
View remediation
Remediation Suggestions
- Create a dedicated temporary directory containing only the generated poster rather than serving
~/Desktop. - Bind the preview server explicitly to the loopback interface:
bash preview_dir="$(mktemp -d)" cp "/path/to/poster.html" "$preview_dir/poster.html" python3 -m http.server 9999 --bind 127.0.0.1 --directory "$preview_dir" - Store and terminate the exact server process ID instead of using the broad pattern-based command
pkill -f, which can affect unrelated matching processes:bash python3 -m http.server 9999 --bind 127.0.0.1 --directory "$preview_dir" & server_pid=$! - Use a shell cleanup trap or equivalent guaranteed-finalization mechanism to terminate the server and remove the temporary directory:
bash cleanup() { kill "$server_pid" 2>/dev/null || true rm -rf -- "$preview_dir" } trap cleanup EXIT INT TERM - Keep the server active only for the minimum time needed to capture the screenshot.
- Where feasible, open the generated file directly through a local
file://URL or use a browser mechanism that does not require an HTTP listener.
- Create a dedicated temporary directory containing only the generated poster rather than serving
