Executive brief
skillctl is a tool used to manage and share 'skills' libraries. Multiple security flaws allowed a malicious library or configuration file to steal sensitive files (like cloud credentials) from a user's computer or delete important folders outside of the project directory. This could occur if a user interacts with a malicious library or merges a compromised configuration file into their project.
Technical details
skillctl versions 0.1.0 and 0.1.1 contain four path-safety vulnerabilities. First, 'fs_util::copy_dir_all' improperly dereferenced symlinks, allowing 'round-trip' exfiltration where local secrets are copied into a project and then pushed to a public library. Second, '.skills.toml' fields were deserialized into 'PathBuf' without validation, allowing absolute paths or '..' traversal to trigger 'remove_dir_all' on arbitrary directories during pull/push operations. Third, the 'detect --target' command failed to block '..' traversal. Finally, fork-name validation accepted '.' and '..' literally, leading to directory clobbering via 'fs::rename'. These issues are fixed in version 0.1.2 by implementing lexical path validation and hard-rejecting symlinks during copy operations.
Affected products
- umanio-agency skillctl 0.1.0, 0.1.1
Timeline
- 2026-05-19: disclosed: Reported privately via Discord
- 2026-05-20: patched: Version 0.1.2 released
- 2026-06-05: advisory: GitHub Advisory published
References
- https://github.com/umanio-agency/skillctl/security/advisories/GHSA-wx3m-whqv-xv47
- https://github.com/umanio-agency/skillctl/commit/827fff5c0698dd9e48e777d5907cf7bc19b91aca
- https://github.com/umanio-agency/skillctl/releases/tag/v0.1.2
- https://api.github.com/repos/umanio-agency/skillctl/security-advisories/GHSA-wx3m-whqv-xv47