T07 · Tool Hijacking and Spoofing
- Location
scripts/flight_offers.py:4- Finding
Working-Directory-Dependent Delegation Enables Local Tool Hijacking
- Content
View full analysis
Vulnerability Details
File Location:
scripts/flight_offers.py:4,scripts/navitia.py:4, andscripts/ev_charge_points.py:4
Vulnerability Type:T07: Tool Hijacking and Spoofing
Risk Level: HighVulnerable code:
python # scripts/flight_offers.py runpy.run_path('skills/air-train-ev/scripts/flight_offers.py', run_name='__main__') # scripts/navitia.py runpy.run_path('skills/air-train-ev/scripts/navitia.py', run_name='__main__') # scripts/ev_charge_points.py runpy.run_path('skills/air-train-ev/scripts/ev_charge_points.py', run_name='__main__')Technical Analysis
All three scripts are alias wrappers that execute another Python file through
runpy.run_path(). The delegated paths are relative paths resolved from the process's current working directory, not paths anchored to the wrapper files or a verified installation directory.The referenced canonical implementation is not included in the audited project. Consequently, its contents and security properties cannot be validated from this artifact. If an attacker can create or modify files under
skills/air-train-ev/scripts/relative to the execution working directory, the wrappers will execute those files as__main__without authenticity or integrity verification.This behavior creates a local tool-hijacking boundary: a legitimate-looking wrapper can be redirected to attacker-controlled Python code merely by controlling the working directory or the expected relative path.
Attack Path
- The attacker obtains write access to the directory from which the wrapper will be launched, or otherwise influences the process's working directory.
- The attacker creates the expected directory structure:
text skills/air-train-ev/scripts/ - The attacker places a malicious file at one or more expected locations, such as:
text skills/air-train-ev/scripts/flight_offers.py - A user or Agent invokes the ...[truncated 1259 chars]
- Remediation
View remediation
Remediation Suggestions
- Package the canonical implementation inside the reviewed Skill or install it as a pinned, integrity-verified dependency.
- Do not resolve executable code relative to the current working directory. Anchor paths to a trusted location using
__file__, for example:python from pathlib import Path import runpy target = ( Path(__file__).resolve().parent / "trusted" / "flight_offers.py" ).resolve() runpy.run_path(str(target), run_name="__main__") - Verify that the resolved target remains beneath an explicitly trusted root before execution, and reject path escapes or unexpected locations.
- Validate the delegated file's integrity using a signed package, trusted manifest, or pinned cryptographic digest.
- Fail closed with a clear error if the canonical implementation is absent; do not search the working directory or fall back to an unverified copy.
- Prefer a normal import from a trusted, pinned Python package over dynamically executing a source path.
- Run the Skill with least privilege and pass only the credentials required for the selected operation.
- Apply the same correction to
scripts/navitia.py:4andscripts/ev_charge_points.py:4.
