mirror of
https://github.com/garrytan/gstack.git
synced 2026-05-10 14:38:24 +08:00
Remove the existence check before mkdir -p (it's idempotent) and validate the target isn't already a symlink before creating the link. Prevents a local attacker from racing between the check and mkdir to redirect SKILL.md writes. Closes C6 from security audit #783. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
28 KiB
Executable File
28 KiB
Executable File