Official agent skill

Path Safety

by microsoft in microsoft/data-formulator

服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。

OfficialMITAuto-check passedDevOps & Cloud

Install Path Safety

skills CLI
$ npx skills add microsoft/data-formulator --skill path-safety -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/data-formulator path-safety --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/data-formulator.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/path-safety .claude/skills/path-safety && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
path-safety
GitHub stars
18k
Token cost
~1.2k tokens
SKILL.md length
159 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。

  • Works in 2 steps: 在 data_loader/init.py 的… → 确保 create_connector() 会拒绝已禁用的类型
  • DevOps & Cloud work in your project
  • SKILL.md covers R1. 文件下载:用…, R2. 路径安全检查:用 ConfinedDir,禁止…, R3. Agent 工具复用… and R4. 优先使用 ConfinedDir,禁止裸路径拼接, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Path Safety is an agent skill from microsoft/data-formulator, published by the product's own GitHub organization. 服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Docker. The repository describes itself as: 🪄 Data Formulator is an interactive AI-powered data analysis system makes it easy to connect, explore and visualize data. The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/path-safety”

Requirements

  • Python 3
  • Docker

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. 在 data_loader/init.py 的 _enforce_deployment_restrictions() 中注册禁用规则
  2. 确保 create_connector() 会拒绝已禁用的类型

What it can do on your machine

Read from SKILL.md and the folder at commit 5477f0e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Path Safety loads about 1.2k tokens when it runs. Until then it costs about 24 tokens; SKILL.md has 159 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~24
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/data-formulator at commit 5477f0e, republished under its MIT licence (© microsoft). 159 words, ~1,165 tokens.

Download SKILL.mdSave it as .claude/skills/path-safety/SKILL.md (or your agent's skills folder).
name
path-safety
description
服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。

Path Safety — 服务端安全编码规范

来源:docs/dev-guides/8-path-safety.md(正式开发规范)+ design-docs/issues/002-arbitrary-file-read-audit.md(安全审计复核)。 本文档提炼了 6 条必须遵守的编码规范。违反任一条即可能引入路径穿越(LFI)漏洞。


R1. 文件下载:用 ConfinedDir.resolve() + send_file,禁用 send_from_directory

原因:send_from_directory(dir, user_input) 内部会对 user_input 二次解析路径,与前置安全检查形成 TOCTOU 不一致。

python
# ❌ BAD — 安全检查用 resolved target,发送用原始 filename,两次解析不一致
target = (scratch_dir / filename).resolve()
target.relative_to(scratch_dir.resolve())  # 检查通过
return send_from_directory(str(scratch_dir), filename)  # 再次解析

# ✅ GOOD — 检查和发送用同一个 resolved path
scratch_jail = workspace.confined_scratch
target = scratch_jail.resolve(filename)
return send_file(target)  # 直接用已验证的路径

send_file(Path) 会根据扩展名自动推断 MIME type,无需额外处理。


R2. 路径安全检查:用 ConfinedDir,禁止 str.startswith

原因:str(path).startswith(str(root)) 存在前缀碰撞缺陷(如 /workspace vs /workspace_evil)。

python
# ❌ BAD
if not str(resolved).startswith(str(root_resolved) + os.sep):
    raise ValueError("escape")

# ✅ GOOD — 统一走 ConfinedDir,内部使用 Path.is_relative_to()
jail = ConfinedDir(root_resolved, mkdir=False)
target = jail.resolve(user_input)

R3. Agent 工具复用 Workspace.confined_*

原因:Agent 工具参数由 LLM 生成,必须视为间接用户输入。不要在工具内手写 Path(root) / rel_path 或 resolve() + relative_to();入口处复用 Workspace 暴露的 ConfinedDir。

python
# ❌ BAD — 手写路径拼接和校验
def _tool_read_file(self, args, workspace_path):
    target = (workspace_path / rel_path).resolve()
    target.relative_to(workspace_path)

# ✅ GOOD — 入口拿到 ConfinedDir,工具只调用 jail.resolve()
def _execute_tool(self, name, args):
    workspace_jail = self.workspace.confined_root
    scratch_jail = self.workspace.confined_scratch
    return self._tool_read_file(args, workspace_jail)

def _tool_read_file(self, args, workspace_jail):
    target = workspace_jail.resolve(args.get("path", ""))

R4. 优先使用 ConfinedDir,禁止裸路径拼接

原因:Path(root) / user_input 是路径穿越的高频入口。ConfinedDir 封装了三层防御(拒绝绝对路径 → 拒绝 .. 段 → resolve + is_relative_to)。

python
from data_formulator.security.path_safety import ConfinedDir

# ❌ BAD — 手动拼接 + 手动校验,容易遗漏
local_file = tmp_path / blob_relative_name
local_file.parent.mkdir(parents=True, exist_ok=True)
local_file.write_bytes(data)

# ✅ GOOD — ConfinedDir 自动校验 + 创建父目录
jail = ConfinedDir(tmp_path, mkdir=False)
jail.write(blob_relative_name, data)  # 自动校验 + 写入
已有安全 API 的层次关系
用户输入(filename / relative_path / blob key)
    │
    ▼
safe_data_filename() / secure_filename()     ← 第一层:输入清洗
    │
    ▼
ConfinedDir.resolve()                        ← 第二层:路径约束
    │
    ▼
安全的 Path 对象

使用 Workspace.get_file_path() 的场景不需要手动调用 ConfinedDir,因为它内部已包含等价的校验。


R5. 宿主文件系统访问必须设部署模式守卫

原因:桌面单用户模式允许访问本机文件系统(预期行为),但多用户/云部署下等于开放服务器读权限。

规范:任何新的 Loader / Connector 如果涉及直接读取宿主文件系统(不通过 Workspace API),必须:

  1. 在 data_loader/__init__.py 的 _enforce_deployment_restrictions() 中注册禁用规则
  2. 确保 create_connector() 会拒绝已禁用的类型
python
# data_loader/__init__.py — 参考 local_folder 的处理方式
def _enforce_deployment_restrictions():
    backend = os.environ.get("WORKSPACE_BACKEND", "local")
    if backend != "local":
        for key in ("local_folder", "your_new_local_loader"):
            if key in DATA_LOADERS:
                del DATA_LOADERS[key]
                DISABLED_LOADERS[key] = f"{key} disabled in multi-user mode"

判断标准:如果 Loader 的构造函数接受一个用户可控的本机路径(如 root_dir),它就需要部署守卫。


R6. 多用户部署必须启用沙箱

原因:not_a_sandbox 模式下 LLM 生成的代码在宿主进程直接执行,可绕过所有路径检查。

app.py 已在启动时检测此配置并输出 logger.critical 警告。新增的沙箱模式或部署脚本应确保:

  • WORKSPACE_BACKEND != "local" 时,SANDBOX 必须为 docker 或 local
  • CI/CD 部署模板中默认设置 SANDBOX=docker

速查:新增代码时的安全检查清单

场景必须做的事
新增文件下载路由用 ConfinedDir.resolve() 得到路径,再 send_file(resolved_path);不用 send_from_directory
新增 Agent 工具(读文件/列目录)入口复用 workspace.confined_root / workspace.confined_scratch,工具内只调用 jail.resolve()
路径包含判断用 ConfinedDir.resolve(),不要手写 Path.is_relative_to() 或 str.startswith()
Path(root) / variable 模式改用 ConfinedDir 或 Workspace.get_file_path()
新增本机文件系统 Loader在 _enforce_deployment_restrictions() 中注册多用户禁用
部署配置多用户模式必须 SANDBOX=docker 或 SANDBOX=local

参考文档

  • docs/dev-guides/8-path-safety.md — 服务端路径安全开发规范
  • design-docs/6-path-safety-confined-dir.md — 剩余未完成实现项状态页
  • design-docs/issues/002-arbitrary-file-read-audit.md — 安全审计复核报告
  • py-src/data_formulator/security/path_safety.py — ConfinedDir 源码

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .cursor/skills/path-safety of microsoft/data-formulator.

Open the folder on GitHubat commit 5477f0e

Compare with similar skills

Path Safety next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Path Safety compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Path Safety this skillmicrosoft/data-formulator18k—~1.2kAutomated safety check: PassMIT
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GreptimeDB Dev Docker ImageGreptimeTeam/greptimedb6.7k—~4kAutomated safety check: NotesApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Build Openshell Mxc WindowsNVIDIA/OpenShell15k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • GreptimeDB Dev Docker Image

    GreptimeTeam/greptimedb

    Packages a locally built GreptimeDB debug binary into a development-only Docker image for local-cluster testing, with an optional push to a dev registry.

    6.7k GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Maintain and validate OpenShell's build-only Windows MSVC lane for x64 and ARM64.

    15k GitHub stars~4.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Container Dev

    yansongda/pay

    A skill your agent uses when local PHP environment is unavailable.

    5.4k GitHub stars~968 tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed

More from microsoft/data-formulator

  • Error Handling

    microsoft/data-formulator

    Official

    统一错误处理系统。在添加 API 端点、修改错误处理、添加前端 API 调用、编写错误相关测试时使用. An agent skill from microsoft/data-formulator.

    18k GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Language Injection

    microsoft/data-formulator

    Official

    LLM Agent 多语言注入规范。在修改 Agent 提示词、添加新的 Agent 端点、处理用户可见的后端消息(messagecode)时使用。

    18k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Data Loading

    microsoft/data-formulator

    Official

    Discover connected data sources, add new data connectors through a user-confirmed form, inspect table metadata, and run bounded read-only probes when the current workspace data is insufficient.

    18k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Report

    microsoft/data-formulator

    Official

    Turn an exploration (threads, findings, charts) into a single Markdown report — note, blog post, executive summary, KPI dashboard, slide brief, or multi-section analytical report, with embedded…

    18k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Core

    microsoft/data-formulator

    Official

    The analyst's built-in capabilities: data-inspection tools and the always-available actions (visualize and askuser).

    18k GitHub stars~5.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Path Safety

What does Path Safety do?

服务端路径安全与文件访问编码规范。在编写文件下载路由、Agent 工具(文件读取/目录列出)、数据连接器/Loader、Workspace 路径操作、沙箱配置时使用。. Path Safety is an agent skill from microsoft/data-formulator, published by the product's own GitHub organization.

When should I use Path Safety?

Path Safety fits situations like: devOps & Cloud work in your project.

How do I install Path Safety in Claude Code?

Run `npx skills add microsoft/data-formulator --skill path-safety -a claude-code`. Or copy the skill folder (.cursor/skills/path-safety in microsoft/data-formulator) into .claude/skills/path-safety in your project. Claude Code loads it when a task matches its description.

How do I install Path Safety in Codex?

Run `npx skills add microsoft/data-formulator --skill path-safety -a codex`. Or copy the skill folder (.cursor/skills/path-safety in microsoft/data-formulator) into .agents/skills/path-safety in your project. Codex loads it when a task matches its description.

Can I use Path Safety in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/data-formulator --skill path-safety -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/path-safety, .gemini/skills/path-safety, .github/skills/path-safety and .opencode/skills/path-safety in your project.

What does Path Safety need to run?

SKILL.md names no scripts, command-line tools or credentials: Path Safety is instructions for the agent only. Our summary lists: Python 3; Docker.

Does Path Safety access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Path Safety safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Path Safety use?

Path Safety is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Path Safety use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Path Safety?

Skills that share tags, products or a category with Path Safety: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GreptimeDB Dev Docker Image (GreptimeTeam/greptimedb, 6.7k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and LangBot Deployment Guide (langbot-app/LangBot, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Path Safety?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/data-formulator, which has 17,540 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 8, 2026.

Source: microsoft/data-formulator on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.