T09 · Insecure Skill Coding Practices
- Location
scripts/smyx_fish_egg_incubation_stage_analysis.py:5- Finding
Arbitrary Code Execution Through Python Import Path Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
scripts/smyx_fish_egg_incubation_stage_analysis.py, lines 5–7 and 16–18
Vulnerability Type: Python import path hijacking through an attacker-writable temporary directory
Risk Level: HighVulnerable Code
python current_dir = os.path.dirname(os.path.abspath(__file__)) parent_dir = os.path.dirname(os.path.dirname(os.path.dirname(current_dir))) sys.path.insert(0, parent_dir) # ... from .config import * from .skill import skill from skills.smyx_common.scripts.util import RequestUtil, OpenIdUtilTechnical Analysis
The entry point derives an import root by traversing three parent directories from the directory containing the script, then inserts the resulting path at the beginning of
sys.path.For the audited project location:
text /tmp/clawhub-codex-scan-v575mhsfx8ypzk0nn07417wa3n8fbvtm-Gs8XLi/artifact/scriptsthe three parent traversals resolve as follows:
text 1. /tmp/clawhub-codex-scan-v575mhsfx8ypzk0nn07417wa3n8fbvtm-Gs8XLi/artifact 2. /tmp/clawhub-codex-scan-v575mhsfx8ypzk0nn07417wa3n8fbvtm-Gs8XLi 3. /tmpConsequently,
/tmpis inserted at index zero of Python's module search path. The entry point subsequently performs absolute imports under theskillsnamespace. Because/tmpis generally writable by other local users, an attacker can place a counterfeitskillspackage there. Python can then load attacker-controlled package initialization code or modules before reaching the legitimate project modules.This is a concrete cross-user trust-boundary violation when the Skill runs from the audited temporary-directory layout. The attacker does not need to modify the Skill package itself; write access to the shared temporary directory is sufficient.
Attack Path
-
A local attacker with write access to
/tmpcreates a counterfeit package hierarchy, for example:text /tmp/skills/__init__.py /tmp/skills/smyx_common/__init__.py /tmp/skills/smyx_co
...[truncated 1463 chars]
-
- Remediation
View remediation
Remediation Suggestions
-
Remove the dynamic
sys.path.insert(0, parent_dir)modification and install or invoke the project as a properly packaged Python module. -
Use package-relative imports where the modules belong to the same trusted distribution.
-
If import-path bootstrapping is unavoidable:
- Resolve the exact project root rather than traversing a fixed number of parent directories.
- Verify that the resolved root is inside the expected project directory.
- Reject shared temporary directories and locations writable by untrusted users.
- Validate directory ownership and permissions before adding it to
sys.path. - Avoid placing the path at index zero unless precedence over installed packages is strictly necessary.
-
Run the Skill from a private directory owned by the invoking account, with permissions preventing modification by other users.
-
Add a startup assertion that imported shared modules originate from the expected project root, for example by validating each module's resolved
__file__path.
-
