T09 · Insecure Skill Coding Practices
- Location
skill.py:2908- Finding
Unrestricted Report Output Can Overwrite Arbitrary Writable Files
- Content
View full analysis
Vulnerability Details
File Location:
skill.py:2908, 2944-2948release_v3.6.1/skill.py:2908, 2944-2948
Vulnerability Type: Unrestricted file overwrite through a user-controlled output path
Risk Level: MediumVulnerable Code
python parser.add_argument('--output', '-o', help='Output file path')python if args.output: Path(args.output).write_text(report, encoding='utf-8') print(f"\nReport saved to: {args.output}") else: print(report)The same implementation is present in both the active source file and the bundled release copy.
Technical Analysis
The
--outputargument accepts an unrestricted filesystem path. That value is passed directly toPath.write_text(), which opens the destination for writing and truncates an existing file before replacing its contents with the generated report.The implementation does not:
- Restrict reports to a dedicated output directory.
- Reject absolute paths or parent-directory traversal.
- Check whether the destination already exists.
- Reject symbolic links.
- Use exclusive file creation.
- Request confirmation before overwriting a file.
Consequently, anyone who can control or influence the command-line arguments can replace any file writable by the Skill process. This behavior also contradicts the package's repeated security guarantee that analysis is read-only and cannot write or modify files.
Attack Path
- An attacker controls or influences the invocation of the Skill, directly or through an automation wrapper.
- The attacker supplies the path of an existing writable file through
--output, for example a project configuration or source file. - The Skill completes its analysis and enters the
if args.outputbranch. Path.write_text()truncates the selected file and replaces it with report data.- The affected application or project may subsequently fail, use corrupted configuration, ...[truncated 834 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove filesystem output for strict read-only operation
- Remove the
--outputoption. - Emit console or JSON reports exclusively through standard output.
- Let a trusted caller handle redirection when persistence is explicitly required.
- Remove the
-
If report files are required, constrain the destination
- Use a dedicated report directory controlled by the application.
- Resolve and validate the destination with
Path.resolve(). - Verify that the resolved path remains inside the approved directory.
- Reject absolute user-supplied paths and parent-directory traversal.
-
Prevent unintended replacement
- Create reports using exclusive creation mode, such as
open(path, "x", encoding="utf-8"). - Reject destinations that already exist unless an explicit, documented overwrite option is supplied.
- Require interactive confirmation where appropriate.
- Create reports using exclusive creation mode, such as
-
Defend against symbolic-link attacks
- Reject symbolic-link destinations and validate relevant parent directories.
- Where supported, use operating-system primitives that prevent following symbolic links.
- Avoid check-then-write sequences that introduce time-of-check/time-of-use races.
-
Align documentation and configuration
- If file output remains available, remove the claims that the Skill performs no file writes.
- Clearly document the exact write behavior, destination restrictions, and overwrite policy.
- Apply the same correction to the duplicated files under
release_v3.6.1/.
-
Add regression tests
- Verify that existing files cannot be overwritten by default.
- Test absolute paths,
..traversal, symbolic links, and destinations outside the approved report directory. - Ensure the active and bundled release implementations remain synchronized.
-
