T08 · Insecure Dependencies
- Location
scripts/submit_dataify_youtube_profiles.py:11- Finding
Untrusted Code Import from an External Sibling Directory
- Content
View full analysis
Vulnerability Details
File Location:
scripts/submit_dataify_youtube_profiles.py, lines 11–14
Vulnerability Type: Untrusted dependency loading and Python import-path manipulation
Risk Level: HighVulnerable Code:
python TASK_RUNTIME_DIR = os.path.abspath(os.path.join(os.path.dirname(__file__), "..", "..", "dataify-task-operations", "scripts")) if TASK_RUNTIME_DIR not in sys.path: sys.path.insert(0, TASK_RUNTIME_DIR) from task_runtime import complete_taskTechnical Analysis
The script constructs a path outside the audited Skill package, places that directory at the beginning of
sys.path, and importstask_runtimefrom it. The external component is not included in the project, version-pinned, or integrity-verified.Inserting the directory at index zero gives modules in that location precedence during Python module resolution. Consequently, a malicious or compromised
task_runtime.pyplaced in the expected sibling directory will execute immediately during import. Python module-level code runs beforemain()and therefore before the script performs its normal validation or network workflow.The imported
complete_taskfunction is later called with both the returned task identifier and the Dataify API token:python final_result = complete_task(task_id, api_token, args.wait_timeout)This directly exposes the credential to code whose implementation and network behavior cannot be verified from the audited project.
Attack Path
- An attacker gains write access to the expected sibling directory, or supplies a compromised
dataify-task-operationscomponent. - The attacker creates or modifies
dataify-task-operations/scripts/task_runtime.py. - A user or agent invokes
scripts/submit_dataify_youtube_profiles.py. - The script prepends the external directory to
sys.path. - Python imports and executes the attacker-controlled module-level code.
- The maliciou ...[truncated 761 chars]
- An attacker gains write access to the expected sibling directory, or supplies a compromised
- Remediation
View remediation
Remediation Suggestions
- Remove the
sys.path.insert(0, TASK_RUNTIME_DIR)behavior. - Bundle the required result-monitoring implementation inside the Skill as a normal package using explicit relative imports.
- Alternatively, obtain the dependency from a trusted package repository and pin an exact version and cryptographic hash.
- Ensure the dependency location is not writable by untrusted users or processes.
- Verify the dependency's integrity before importing it if an external runtime is unavoidable.
- Avoid passing the long-lived API token to a broad helper module. Expose only the narrowly scoped operation required for task monitoring.
- Document every network destination used during result monitoring and restrict outbound requests to an explicit allowlist.
- Add installation or startup checks that fail closed if the trusted dependency is absent or fails integrity verification.
- Remove the
