Back to skill

Security audit

Auto Llm 4891

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a simple Chinese-language AI-agent learning stub, but its executable Python file includes an unnecessary module-search-path change that could let local code hijack an import.

Review this before installing. The learning links and simple chatbot behavior are not inherently dangerous, but the Python file should remove the hard-coded sys.path insertion before use. If installed as-is, only run it in an environment where D:\\coze-local\\db cannot be written by untrusted users.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Warning
Location
auto_llm_4891.py:6
Finding

Untrusted Module Search Path Enables Local Module Hijacking

Content
View full analysis

Vulnerability Details

File Location: auto_llm_4891.py, lines 6-9
Vulnerability Type: Untrusted Python module search path
Risk Level: Medium

python
import sys
sys.path.insert(0, r"D:\\coze-local\\db")

import random

Technical Analysis

The script prepends an unrelated, hard-coded directory to sys.path before importing random. Position zero has the highest module-resolution priority. Consequently, Python may load a file such as random.py from that directory instead of the intended standard-library module.

Python executes a module's top-level code during import. An attacker who can write to the inserted directory could therefore place a spoofed module there and obtain code execution when this skill is imported or invoked. The path modification is not required by the documented or implemented chatbot functionality.

Exploitation depends on the path being usable in the runtime environment and the attacker having permission to write to it.

Attack Path

  1. The attacker obtains write access to the effective D:\coze-local\db directory.
  2. The attacker creates a malicious random.py file in that directory.
  3. A user or agent starts or imports auto_llm_4891.py.
  4. The script inserts the attacker-influenced directory at the beginning of sys.path.
  5. The subsequent import random resolves to the attacker's file instead of the trusted standard-library module.
  6. Python executes the malicious module's top-level code within the skill process.

Impact Assessment

Successful exploitation permits arbitrary Python code execution with the same operating-system identity, filesystem access, environment access, and network permissions as the process running the skill. Depending on those privileges, the attacker could access or alter process-readable data and perform any other action available to that account. This code does not itself elevate privileges; the impact is bounded by the privileg ...[truncated 87 chars]

Remediation
View remediation

Remediation Suggestions

Remove the unnecessary search-path modification:

python
import random

If project-specific modules are genuinely required:

  • Package them as part of the project and use explicit package-relative imports.
  • Install dependencies into a controlled virtual environment from pinned, verified sources.
  • Never prepend shared, user-writable, temporary, or unrelated directories to sys.path.
  • Ensure application and dependency directories are writable only by trusted administrators or deployment identities.
  • Run the skill under a least-privileged account to limit the consequences of any future import-hijacking issue.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and all instructional content are presented entirely in Chinese, including the trigger context and learning materials, with no indication that users may choose another language. This is a natural-language policy concern because it imposes a specific language/locale without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The top-level docstring contains only Chinese-language instructional/promotional text and does not indicate any user opt-in, language selection, or region-specific requirement. This can violate language/locale policy when a skill is expected to be language-neutral or to respect user preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.