Skip to content

fix(security): skip hidden directories in skill template discovery - #433

Closed
HMAKT99 wants to merge 1 commit into
garrytan:mainfrom
HMAKT99:arun/fix-discover-hidden-dirs
Closed

HMAKT99 wants to merge 1 commit into
garrytan:mainfrom
HMAKT99:arun/fix-discover-hidden-dirs

Conversation

@HMAKT99

@HMAKT99 HMAKT99 commented Mar 24, 2026

Copy link
Copy Markdown
Contributor

Summary

  • discoverTemplates() in scripts/discover-skills.ts scans subdirectories for .tmpl files
  • SKIP set only blocks node_modules, .git, dist
  • Hidden directories (.claude/, .agents/, .codex/) were being scanned
  • These contain symlinked skill installs — a malicious .tmpl in a symlinked skill directory would be discovered and processed by gen-skill-docs

Fix

- .filter(d => d.isDirectory() && !SKIP.has(d.name))
+ .filter(d => d.isDirectory() && !d.name.startsWith('.') && !SKIP.has(d.name))

Skips all dot-prefixed directories. All 28 legitimate skills still generate. All tests pass.

1 file, 1 line changed

scripts/discover-skills.ts

Test plan

  • All existing tests pass (0 fail)
  • 28 Claude skills still generate
  • 27 Codex skills still generate
  • .claude/, .agents/, .codex/ directories skipped

discoverTemplates() scans subdirectories for SKILL.md.tmpl files but
only skips node_modules, .git, and dist. Hidden directories like
.claude/, .agents/, and .codex/ (which contain symlinked skill
installs) were being scanned, allowing a malicious .tmpl in a
symlinked skill to inject into the generation pipeline.

Fix: add !d.name.startsWith('.') to the subdirs() filter. This skips
all dot-prefixed directories, matching the standard convention that
hidden dirs are not source code.
@garrytan

Copy link
Copy Markdown
Owner

Thanks @HMAKT99 — your fix is in main: scripts/discover-skills.ts:13 has the exact !d.name.startsWith('.') filter. Closing as superseded; sorry we didn't link your PR at merge time. Credit retained here.

@garrytan garrytan closed this May 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants