T07 · Tool Hijacking and Spoofing
- Location
scripts/smyx_fish_gasping_ammonia_warning_analysis.py:2- Finding
World-Writable Directory Prepending Enables Python Module Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
scripts/smyx_fish_gasping_ammonia_warning_analysis.py, lines 2–23
Vulnerability Type: Python module search-path hijacking
Risk Level: MediumVulnerable Code
python import sys import os current_dir = os.path.dirname(os.path.abspath(__file__)) parent_dir = os.path.dirname(os.path.dirname(os.path.dirname(current_dir))) sys.path.insert(0, parent_dir) import argparse import json import mimetypes import traceback from datetime import datetime import requests import sys import os from .config import * from .skill import skill from skills.smyx_common.scripts.util import RequestUtil, OpenIdUtilTechnical Analysis
The entry point ascends three directory levels from its own directory and prepends the resulting path to Python's module search path.
In the audited deployment layout, the script is located at:
text /tmp/clawhub-codex-scan-v571h9h0jptdvfxd0we9b49zv58f6eyy-pdbrLt/artifact/scripts/Ascending three levels resolves
parent_dirto/tmp. The call to:python sys.path.insert(0, parent_dir)therefore places a generally world-writable directory ahead of trusted package locations. Subsequent imports, including
requestsandskills.smyx_common..., may resolve to attacker-created modules or packages in/tmp.Python executes top-level module code during import. Consequently, a local attacker who can create files in
/tmpcan arrange for arbitrary Python code to execute when the documented Skill entry point is invoked. The malicious module does not need to modify the audited project itself.Attack Path
- A lower-privileged local attacker determines that the Skill is installed under the audited temporary-directory structure.
- The attacker creates a malicious import candidate in
/tmp, such as:/tmp/requests.py; or- a spoofed
/tmp/skills/package with the expected module hi ...[truncated 1474 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the manual
sys.pathmodification and invoke the entry point as part of an installed or properly configured Python package. -
Use a package entry point or execute the module from the trusted project root:
bash python -m scripts.smyx_fish_gasping_ammonia_warning_analysisEnsure the project root is supplied through a controlled installation mechanism rather than inferred by traversing into
/tmp. -
If path adjustment is unavoidable, calculate the exact project root rather than ascending beyond it:
python from pathlib import Path project_root = Path(__file__).resolve().parents[1]Before adding it, verify that the resolved directory is the expected project root and is not writable by untrusted users.
-
Do not prepend shared or world-writable directories to
sys.path. Reject paths such as/tmp,/var/tmp, or directories with unsafe ownership or write permissions. -
Install the Skill in a directory owned by the Agent account or an administrator, with write access denied to unrelated local users.
-
Run Python in isolated mode where compatible, and use a dedicated virtual environment with explicitly installed dependencies to reduce ambient import-path influence.
-
Add a regression test that resolves the calculated project root and fails if it points outside the Skill installation directory or into a world-writable location.
-
