T09 · Insecure Skill Coding Practices
- Location
SKILL.md:40- Finding
Unconfirmed Deletion of User-Owned Project Files
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 40–53; related instruction at line 245
Vulnerability Type: Destructive file operation without mandatory confirmation
Risk Level: MediumVulnerable Instruction:
markdown Before touching docs, clean non-documentation clutter from the project root. Root-level noise (screenshots, recordings, debug logs, AI chat exports) is often the biggest source of visual chaos — and it has nothing to do with documentation structure. Run `ls | wc -l` and capture the count. Then identify and relocate: | What to look for | Where it goes | |-----------------|---------------| | Screenshots, recordings (`.png`, `.mov`, `.mp4`) | `archive/media/` or `screenshots/` if curated | | Debug/build logs (`*.log`, `firebase-debug.log`) | `archive/` or delete | | AI chat exports, temp markdown dumps | `archive/` or delete | | One-off config experiments | `archive/` or delete | Do this first — it dramatically reduces root-level item count and makes the real structure visible before you start reorganizing docs.A related instruction at line 245 states:
markdown | Chat logs in `docs/` | Not documentation | Move to `archive/` or delete |Technical Analysis
The Skill is intended to reorganize project documentation, but its mandatory preliminary workflow instructs the Agent to clean the project root and permits deletion of broadly defined file classes. Terms such as “temp markdown dumps” and “one-off config experiments” are subjective and can include valuable drafts, configuration work, diagnostic evidence, or operational records.
The instructions do not require a dry run, an exact candidate-file inventory, per-file approval, backups, or use of a recoverable deletion mechanism. A textual recommendation to either archive or delete does not technically enforce the safer choice. Consequently, an Agent following the Skill may select deletion without obtainin ...[truncated 1659 chars]
- Remediation
View remediation
Remediation Suggestions
- Make archival, rather than deletion, the mandatory default for every candidate file.
- Require the Agent to present an exact list of files and proposed destinations before making changes.
- Require explicit user confirmation before deleting any file, with deletion approval scoped to individually identified paths.
- Use a recoverable trash mechanism or create a backup instead of performing permanent deletion.
- Exclude configuration files, logs, and diagnostic records from automatic deletion unless the user explicitly requests their removal.
- Add a dry-run phase that reports classifications, proposed moves, and proposed deletions without modifying the workspace.
- Replace subjective categories with narrow matching rules and require manual review where classification is uncertain.
