T09 · Insecure Skill Coding Practices
- Location
scripts/gh_accel.sh:153- Finding
Failed clone attempts can recursively delete pre-existing directories
- Content
View full analysis
$dir" return 0 fi rm -rf "$dir" echo " ✗ 直连失败,降级镜像…" fi for base in "${CLONE_PROXIES[@]}"; do echo "→ 镜像: $base/$repo" if git clone "$base/$repo" "$dir"; then echo "✅ 经镜像 clone 成功 -> $dir" echo "⚠️ remote 指向镜像,push 前执行:" echo " git -C $dir remote set-url origin https://github.com/$repo.git" return 0 fi rm -rf "$dir" echo " ✗ 失败" done ``` ### Technical Analysis The clone destination is derived from the user-supplied `dir` argument. After every failed `git clone`, the script executes `rm -rf "$dir"` without establishing that the directory was created by the current invocation. If the destination already exists, `git clone` ordinarily fails because the destination is nonempty. The subsequent cleanup then recursively removes that pre-existing directory. Quoting prevents shell argument injection, but it does not make deletion of an attacker-selected path safe. The implementation has no checks for: - A destination that existed before the command started. - Root, home, current-working-directory, or parent-directory targets. - Symbolic-link or path-resolution concerns. - Whether the current process created the directory. - Whether the failed clone wrote anything into the destination. ### Attack Path 1. An attacker persuades the user or Agent to invoke the Skill with an existing writable directory as the clone destination. 2. For example: ```bash scripts/gh_accel.sh clone OWNER/REPO /home/user/important-project ``` 3. `git clone` fails because the destination already exists and is nonempty. 4. The script executes: ```bash rm -rf "/home/user/i ...[truncated 683 chars]- Remediation
View remediation
