Skip to main content

hunting-unsafe-archive-extraction

Hunt unsafe extraction of untrusted compressed archives: an entry's declared path escaping the destination directory (traversal or an absolute path), a symlink or hardlink entry that a later entry writes through to reach outside, decompression amplification where a small archive expands to exhaust disk or memory, and content or name confusion where an extracted file is later executed, served, or loaded. Covers import, restore, plugin-install, and upload features that unpack archives from users or remote sources, and the difference between checking a path and checking the path a symlink resolves to. Use when reviewing code that extracts an archive whose contents come from an untrusted source. The archive entry's path, link target, or declared size is the source, the filesystem write or allocation during extraction is the sink, and the missing containment check is the bug.

Jump to install

Source facts

Repository
UnboundCompute/security-agent-skills
Last source activity
August 21, 2026 at 08:02
Detected SKILL.md language
English
Stars
4
Forks
2

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.