T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:53- Finding
Untrusted Python Module Execution Through Attacker-Controlled PYTHONPATH
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 53–57
Vulnerability Type: Untrusted local tool/module hijacking
Risk Level: Highbash PYTHONPATH="$(find . -path '*/conserve/scripts' -type d \ -print -quit 2>/dev/null || \ echo 'plugins/conserve/scripts')" \ python3 -m context_scanner .Technical Analysis
The documented procedure searches the project being inspected for the first directory matching
*/conserve/scripts, places that directory inPYTHONPATH, and then executes thecontext_scannermodule withpython3 -m.Because the scanned project is untrusted input, an attacker can add a directory such as
conserve/scriptscontaining a maliciouscontext_scanner.pymodule. Python will resolve and execute that attacker-controlled module under the privileges of the user or agent running the skill. The discovered path is neither restricted to a trusted plugin installation nor authenticated before execution.This converts what appears to be a project-analysis operation into an arbitrary local code-execution primitive.
Attack Path
- An attacker adds
conserve/scripts/context_scanner.pyto a repository. - A user or agent opens that repository and invokes the context-map skill.
- The
findcommand discovers the attacker-controlledconserve/scriptsdirectory. - The command prepends that directory to
PYTHONPATH. python3 -m context_scanner .imports and executes the malicious module.- The module runs with the invoking user's permissions and can access any resources available to that process.
Impact Assessment
Successful exploitation provides arbitrary code execution with the privileges of the user or agent invoking the skill. Depending on the execution environment, an attacker could:
- Read source code, configuration files, credentials, and environment variables accessible to the process.
- Modify or delete workspace files.
- Tamper with generated analysis results.
- Execute additional local ...[truncated 310 chars]
- An attacker adds
- Remediation
View remediation
Remediation Suggestions
- Do not derive executable module paths from the untrusted project being scanned.
- Resolve
context_scannerfrom a fixed, absolute installation path outside the target repository. - Invoke a trusted scanner using an absolute script or executable path, and pass the project root only as a data argument.
- Validate that the trusted scanner path is owned by an expected user or package and is not writable by the scanned project.
- Pin and verify the scanner package or artifact using an approved package source and integrity checks.
- Sanitize inherited Python import settings such as
PYTHONPATHand consider isolated mode where compatible. - Run project scanning in a sandbox with minimal filesystem permissions, no unnecessary credentials, and restricted network access.
- Fail safely when the trusted scanner is unavailable instead of falling back to a path inside the target project.
A safer invocation pattern is conceptually:
bash env -u PYTHONPATH python3 -I /absolute/trusted/path/context_scanner.py .The exact command should use the verified installation location appropriate to the deployment environment.
