T07 · Tool Hijacking and Spoofing
- Location
knowledge_bridge.py:7- Finding
Arbitrary Module Loading Through a Precedence-Controlled External Search Path
- Content
View full analysis
Vulnerability Details
File Location:
knowledge_bridge.py, lines 7 and 15–20
Vulnerability Type: Untrusted Python module search-path manipulation
Risk Level: HighVulnerable Code
python _SRC = Path(__file__).parent.parent.parent / "db"python sys.path.insert(0, str(_SRC)) try: from knowledge_bridge import ( ingest_latest_cycle, get_kb_stats, search_knowledge, backfill_all_cycles, auto_explain )Technical Analysis
The skill derives a directory outside its package, inserts that directory at index zero of
sys.path, and then imports an unqualified module namedknowledge_bridge. Index zero has the highest normal import priority, so a file namedknowledge_bridge.pyin that external directory can replace the expected implementation.In the audited deployment path, the expression resolves to
/tmp/db. This directory is outside the reviewed project. If an attacker can create or replace/tmp/db/knowledge_bridge.py, Python will execute that file's top-level statements during import. The imported functions subsequently receive control over every advertised operation, including ingestion, statistics, backfill, search, and explanation.The external implementation is not included in the project, so its database, network, and data-handling behavior cannot be verified. The project contains no direct evidence of malicious payloads, persistence, credential theft, or exfiltration; the risk arises from the unsafe loading mechanism.
Attack Path
- An attacker obtains write access to the derived external module directory.
- The attacker creates or replaces
/tmp/db/knowledge_bridge.py. - The attacker defines the expected exported function names and adds malicious top-level code or malicious function bodies.
- A user or Agent invokes any skill operation.
- The skill prepends
/tmp/dbtosys.path. - Python resolves
from knowledge_bridge import ...to the attacker-controlled file and immediate ...[truncated 984 chars]
- Remediation
View remediation
Remediation Suggestions
-
Package the implementation inside the skill under a unique package name and use an explicit relative import, for example:
python from .bridge_backend import ( ingest_latest_cycle, get_kb_stats, search_knowledge, backfill_all_cycles, auto_explain, ) -
Remove runtime mutation of
sys.path. In particular, do not prepend externally derived or temporary directories to the import search path. -
If an external implementation is operationally required:
- Configure its location explicitly rather than deriving it through parent traversal.
- Require an absolute, canonical path.
- Restrict the path to an administrator-controlled, non-world-writable directory.
- Verify file ownership and reject files writable by untrusted users.
- Verify the module against a pinned cryptographic digest or trusted signature before loading it.
- Load it under a unique internal module name and fail closed on any verification failure.
-
Avoid naming the wrapper and external backend module
knowledge_bridge, as the duplicate name increases import ambiguity and spoofing risk. -
Add deployment tests that resolve and record the exact imported module path, rejecting any module located outside the approved application directory.
-
Align
SKILL.mdwith the actual loading behavior. The documentation currently describes Windows paths underD:\coze-local, while the code derives an environment-dependent externaldbdirectory.
-
