Skip to content

scan --output can overwrite its local input file #728

Description

@YMuskrat

skillspector scan SKILL.md --no-llm --output report.txt reads a skill and writes a separate report. If the output is accidentally set to SKILL.md instead, the current CLI silently replaces the original skill with the report and exits successfully.

This is accidental data loss: the file being inspected is destroyed while saving the inspection result.

Reproduction

On main at 4a5506276795397c62ed4f0111c08f41c2b9f1b1, use a temporary directory:

demo_dir="$(mktemp -d)"
cd "$demo_dir"
cat > SKILL.md <<'EOF'
---
name: hello
description: Say hello.
---

# Hello
Say hello to the user.
EOF
cp SKILL.md original.md
skillspector scan SKILL.md --no-llm --output SKILL.md
cmp SKILL.md original.md

Expected: reject the conflicting output destination, ask for a different path, and leave the original skill unchanged.

Actual: the scan exits 0; SKILL.md contains the terminal report, and cmp reports that it differs from the original.

I also reproduced the overwrite when a differently named output is a symbolic link or hard link to the input. Comparing only path strings would miss those cases. Relative paths and paths containing .. can also identify the same file.

The regular scan command should validate a local file input against an existing output's file identity before scanning or writing. A separate destination should continue to work, including an existing report file or a file with the same name in another directory.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions