Back to skill

Security audit

air_train_ev

Security checks for vulnerabilities and agentic risk

Overview

This travel alias skill is disclosed, but its scripts can execute another local Python file from the current working directory, which needs review before installation.

Install only if you intentionally have and trust the canonical air-train-ev skill at the expected path. Review that canonical skill and consider fixing these wrappers to resolve paths relative to a trusted install location before using API credentials with them.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/flight_offers.py:4
Finding

Working-Directory-Dependent Delegation Enables Local Tool Hijacking

Content
View full analysis

Vulnerability Details

File Location: scripts/flight_offers.py:4, scripts/navitia.py:4, and scripts/ev_charge_points.py:4
Vulnerability Type: T07: Tool Hijacking and Spoofing
Risk Level: High

Vulnerable code:

python
# scripts/flight_offers.py
runpy.run_path('skills/air-train-ev/scripts/flight_offers.py', run_name='__main__')

# scripts/navitia.py
runpy.run_path('skills/air-train-ev/scripts/navitia.py', run_name='__main__')

# scripts/ev_charge_points.py
runpy.run_path('skills/air-train-ev/scripts/ev_charge_points.py', run_name='__main__')

Technical Analysis

All three scripts are alias wrappers that execute another Python file through runpy.run_path(). The delegated paths are relative paths resolved from the process's current working directory, not paths anchored to the wrapper files or a verified installation directory.

The referenced canonical implementation is not included in the audited project. Consequently, its contents and security properties cannot be validated from this artifact. If an attacker can create or modify files under skills/air-train-ev/scripts/ relative to the execution working directory, the wrappers will execute those files as __main__ without authenticity or integrity verification.

This behavior creates a local tool-hijacking boundary: a legitimate-looking wrapper can be redirected to attacker-controlled Python code merely by controlling the working directory or the expected relative path.

Attack Path

  1. The attacker obtains write access to the directory from which the wrapper will be launched, or otherwise influences the process's working directory.
  2. The attacker creates the expected directory structure:
    text
    skills/air-train-ev/scripts/
    
  3. The attacker places a malicious file at one or more expected locations, such as:
    text
    skills/air-train-ev/scripts/flight_offers.py
    
  4. A user or Agent invokes the ...[truncated 1259 chars]
Remediation
View remediation

Remediation Suggestions

  1. Package the canonical implementation inside the reviewed Skill or install it as a pinned, integrity-verified dependency.
  2. Do not resolve executable code relative to the current working directory. Anchor paths to a trusted location using __file__, for example:
    python
    from pathlib import Path
    import runpy
    
    target = (
        Path(__file__).resolve().parent
        / "trusted"
        / "flight_offers.py"
    ).resolve()
    runpy.run_path(str(target), run_name="__main__")
    
  3. Verify that the resolved target remains beneath an explicitly trusted root before execution, and reject path escapes or unexpected locations.
  4. Validate the delegated file's integrity using a signed package, trusted manifest, or pinned cryptographic digest.
  5. Fail closed with a clear error if the canonical implementation is absent; do not search the working directory or fall back to an unverified copy.
  6. Prefer a normal import from a trusted, pinned Python package over dynamically executing a source path.
  7. Run the Skill with least privilege and pass only the credentials required for the selected operation.
  8. Apply the same correction to scripts/navitia.py:4 and scripts/ev_charge_points.py:4.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
# Alias — air_train_ev → air-train-ev

This skill is an **alias** for the canonical skill:
- `skills/air-train-ev/SKILL.md`

Use the same scripts (do not duplicate logic):
- Flights (Amadeus): `skills/air-train-ev/scripts/flight_offers.py`

Static analysis

No suspicious patterns detected.