T09 · Insecure Skill Coding Practices
- Location
main.py:14- Finding
Import-Time Deletion of Files in the Current Working Directory
- Content
View full analysis
Vulnerability Details
File Location:
main.py, lines 14-23
Vulnerability Type: Unsafe file deletion and import-time side effects
Risk Level: HighVulnerable Code
python try: temp_files = ["1.png", "2.png", "3.png", "bg.png", "bg1.png", "bg2.png", "bg3.png", "bg4.png", "bg5.png", "bg6.png", "bg7.png", "bg8.png", "bg9.png", "bg10.png", "bg11.png"] for f in temp_files: if os.path.exists(f): os.remove(f) except: passTechnical Analysis
The cleanup logic executes at module import time rather than only when the application is explicitly run. Every filename is relative, so Python resolves it against the process's current working directory rather than a dedicated application workspace.
The names are generic and may correspond to unrelated user files. Consequently, importing
main.pyfrom another application or running the program from a directory containing files such as1.png,2.png, orbg.pngcan irreversibly delete those files. The unrestrictedexceptblock suppresses errors and makes the destructive behavior difficult to diagnose.Attack Path
- A user or integrating application places or already has an unrelated image named
1.png,bg.png, or another listed name in its working directory. - The user executes the Skill from that directory, or another Python component imports
main.py. - Python immediately executes the module-level cleanup logic.
- Matching files are deleted before the guarded
if __name__ == "__main__"workflow begins. - Any deletion errors are silently suppressed.
No attacker-controlled path traversal is required. The vulnerability arises from the collision between generic filenames and the caller's working directory.
Impact Assessment
The code can delete matching files writable by the current process. It does not elevate privileges, so its scope is limited to fil ...[truncated 209 chars]
- A user or integrating application places or already has an unrelated image named
- Remediation
View remediation
Remediation Suggestions
- Move cleanup into an explicit
main()function so importing the module has no destructive side effects. - Create a unique temporary workspace with
tempfile.TemporaryDirectory()for each run. - Resolve every generated path beneath that workspace and verify containment before deletion.
- Track files created by the current execution and delete only those files.
- Avoid generic output names in the caller's current working directory.
- Do not overwrite or delete an existing user file without explicit confirmation.
- Replace the bare
exceptwith specific exception handling and report cleanup failures.
- Move cleanup into an explicit
