T09 · Insecure Skill Coding Practices
- Location
auto_llm_4712.py:5- Finding
External Module Search-Path Precedence Enables Arbitrary Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
auto_llm_4712.py, lines 5-11
Vulnerability Type: Untrusted module loading through Python search-path manipulation
Risk Level: HighVulnerable Code:
python import sys sys.path.insert(0, r"D:\\coze-local\\db") def run(param=""): """AI 大模型周报 2026年5月 e(附链接)""" print(f"[auto_llm_4712] AI 大模型周报 2026年5月 e(附链接)") from learn import KnowledgeBaseTechnical Analysis
The script inserts the hard-coded external directory
D:\coze-local\dbat index zero ofsys.path. Python will consequently search this directory before standard package locations when resolvingfrom learn import KnowledgeBase.The
learnmodule is not included in the audited project, so its implementation and integrity cannot be verified. If an attacker can create or modifylearn.py, or a matchinglearnpackage, in the external directory, Python will execute attacker-controlled module-level code as soon as the import occurs. Attacker-controlled behavior may also execute whenKnowledgeBaseis instantiated or its methods are called.This is an insecure module-loading pattern because the effective executable code is determined by mutable state outside the audited package.
Attack Path
- An attacker obtains write access to
D:\coze-local\db, whether through permissive directory permissions, another compromised process, or an existing account with access. - The attacker creates or replaces
learn.py, or creates alearnpackage, containing malicious Python code and a compatibleKnowledgeBasesymbol. - A user or Agent invokes
auto_llm_4712.py. - The script places the attacker-controlled directory first in
sys.path. from learn import KnowledgeBaseresolves to the attacker's module.- Python executes the malicious module under the privileges of the process running the skill.
Impact Assessment
Successful exploitation permits arbitrary Python c ...[truncated 570 chars]
- An attacker obtains write access to
- Remediation
View remediation
Remediation Suggestions
- Remove the runtime
sys.path.insert()modification. - Package
learnas part of the skill or install it as a pinned, trusted dependency through the deployment system. - Import the dependency through an explicit package namespace rather than an ambiguous top-level module name.
- Verify dependency integrity using locked versions and cryptographic hashes.
- Ensure application directories and dependency locations are not writable by untrusted users.
- Fail closed when the trusted dependency is unavailable instead of searching mutable external locations.
- If external loading is unavoidable, resolve a canonical path, verify ownership and permissions, validate an expected cryptographic digest, and load only the verified file.
- Remove the runtime
