Back to skill

Security audit

Reptile Feeding Refusal / Vomiting Detection | 爬宠进食拒绝/呕吐识别

Security checks for vulnerabilities and agentic risk

Overview

The skill is a cloud-backed reptile video analyzer, but it silently creates/reuses identities, stores tokens locally, and sends media or URLs to an external service with under-scoped disclosure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/smyx_reptile_feeding_refusal_vomiting_analysis.py:6
Finding

Python Module Hijacking Through a Shared Temporary Directory

Content
View full analysis

Vulnerability Details

File Location: scripts/smyx_reptile_feeding_refusal_vomiting_analysis.py, lines 6–13
Vulnerability Type: Untrusted Python import path injection
Risk Level: High

Vulnerable Code

python
current_dir = os.path.dirname(os.path.abspath(__file__))
parent_dir = os.path.dirname(os.path.dirname(os.path.dirname(current_dir)))
sys.path.insert(0, parent_dir)

import argparse
import json
import mimetypes
import traceback
from datetime import datetime

import requests

Technical Analysis

The entry point calculates a directory three levels above its own location and prepends that directory to sys.path. In the audited deployment path, this calculation resolves to /tmp, which is ordinarily writable by other local users.

Because the directory is inserted at index zero before subsequent imports, Python searches /tmp before the standard library and installed package directories. A local attacker could therefore place a malicious module or package there using a name imported by the entry point or its dependencies, such as requests.py, argparse.py, or a forged skills package.

Importing the attacker-controlled module executes its top-level Python code under the identity and privileges of the user invoking the Skill. The issue is reachable whenever the documented module entry point is launched from the supplied project location.

Attack Path

  1. The project is deployed at the audited path beneath /tmp.

  2. An unprivileged local attacker with write access to /tmp creates a malicious module such as /tmp/requests.py.

  3. A user invokes the documented entry point:

    bash
    python -m scripts.smyx_reptile_feeding_refusal_vomiting_analysis --input feeding.mp4
    
  4. The entry point prepends /tmp to sys.path.

  5. The subsequent import requests resolves to the attacker's /tmp/requests.py instead of the legitimate dependency.

  6. Python executes the attacker's top-level code with the invoking user's pri ...[truncated 889 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the dynamic sys.path modification and package the project so it can be imported through normal Python package resolution.
  • Install the package into a virtual environment or invoke it from a trusted project root without adding ancestor directories to sys.path.
  • If bootstrapping is unavoidable, resolve and add the exact project root rather than traversing a fixed number of parent directories.
  • Before adding a directory, verify that it is the expected trusted path and is not writable by untrusted users.
  • Avoid prepending broad directories such as /tmp; use the narrowest possible trusted package directory.
  • Deploy the Skill outside shared writable directories and ensure the project tree and its parent directories have restrictive ownership and permissions.
  • Add a regression test that verifies imported modules resolve to the intended standard-library, dependency, and project paths.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2