T09 · Insecure Skill Coding Practices
- Location
scripts/smyx_reptile_feeding_refusal_vomiting_analysis.py:6- Finding
Python Module Hijacking Through a Shared Temporary Directory
- Content
View full analysis
Vulnerability Details
File Location:
scripts/smyx_reptile_feeding_refusal_vomiting_analysis.py, lines 6–13
Vulnerability Type: Untrusted Python import path injection
Risk Level: HighVulnerable Code
python current_dir = os.path.dirname(os.path.abspath(__file__)) parent_dir = os.path.dirname(os.path.dirname(os.path.dirname(current_dir))) sys.path.insert(0, parent_dir) import argparse import json import mimetypes import traceback from datetime import datetime import requestsTechnical Analysis
The entry point calculates a directory three levels above its own location and prepends that directory to
sys.path. In the audited deployment path, this calculation resolves to/tmp, which is ordinarily writable by other local users.Because the directory is inserted at index zero before subsequent imports, Python searches
/tmpbefore the standard library and installed package directories. A local attacker could therefore place a malicious module or package there using a name imported by the entry point or its dependencies, such asrequests.py,argparse.py, or a forgedskillspackage.Importing the attacker-controlled module executes its top-level Python code under the identity and privileges of the user invoking the Skill. The issue is reachable whenever the documented module entry point is launched from the supplied project location.
Attack Path
-
The project is deployed at the audited path beneath
/tmp. -
An unprivileged local attacker with write access to
/tmpcreates a malicious module such as/tmp/requests.py. -
A user invokes the documented entry point:
bash python -m scripts.smyx_reptile_feeding_refusal_vomiting_analysis --input feeding.mp4 -
The entry point prepends
/tmptosys.path. -
The subsequent
import requestsresolves to the attacker's/tmp/requests.pyinstead of the legitimate dependency. -
Python executes the attacker's top-level code with the invoking user's pri ...[truncated 889 chars]
-
- Remediation
View remediation
Remediation Suggestions
- Remove the dynamic
sys.pathmodification and package the project so it can be imported through normal Python package resolution. - Install the package into a virtual environment or invoke it from a trusted project root without adding ancestor directories to
sys.path. - If bootstrapping is unavoidable, resolve and add the exact project root rather than traversing a fixed number of parent directories.
- Before adding a directory, verify that it is the expected trusted path and is not writable by untrusted users.
- Avoid prepending broad directories such as
/tmp; use the narrowest possible trusted package directory. - Deploy the Skill outside shared writable directories and ensure the project tree and its parent directories have restrictive ownership and permissions.
- Add a regression test that verifies imported modules resolve to the intended standard-library, dependency, and project paths.
- Remove the dynamic
