mediumCVSS 6.5Vulnerability

GHSA-6xx4-9wp6-65p7

### Impact `skilo add` installs a skill by recursively copying the skill directory into the target skills directory. The copy routine (`copy_dir_all`) classified each entry with `std::fs::DirEntry::file_type()` — which does **not** follow symlinks — and then copied non-directory entries with `std::fs::copy()`, which **does** dereference symlinks. As a result, a skill containing a symbolic link such as `reference.txt -> /home/<user>/.ssh/id_rsa` was copied as a regular file whose contents are the link's **target**. A malicious skill source — for example a git repository installed via `skilo add github.com/<attacker>/<skills>`, or a local path — could read arbitrary files readable by the user running `skilo add` (SSH keys, cloud credentials, `.env` files, etc.) and place their contents inside the installed skill directory, where the user or their agent may later read, share, or sync them. This is arbitrary local file disclosure (CWE-59 / CWE-61, symlink following) triggered by installing an untrusted skills source. ### Patches Fixed in **0.11.1**. `copy_dir_all` now rejects symbolic-link entries at any recursion depth (failing closed with a dedicated error) instead of dereferencing them. ### Workarounds - Only install skills from sources you trust. - Inspect a skill source for symbolic links before running `skilo add`. ### Affected versions Introduced together with the `skilo add` command in 0.5.0 and present through 0.11.0. Releases before 0.5.0 do not include the `add` command.

Properties

ghsa_id
GHSA-6xx4-9wp6-65p7
severity
medium
summary
skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source
cvss_score
6.5
cve_id
GHSA-6xx4-9wp6-65p7
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-07-28T22:23:48Z
source_url
https://github.com/advisories/GHSA-6xx4-9wp6-65p7
ghsa_updated
2026-07-28T22:23:50Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]rust/skilo

AFFECTS (1)

[Software]rust/skilo

HAS_WEAKNESS (2)

[Weakness]UNIX Symbolic Link (Symlink) Following
[Weakness]Improper Link Resolution Before File Access ('Link Following')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph