T09 · Insecure Skill Coding Practices
- Location
scripts/run_byte_gate.py:17- Finding
Environment-Controlled Execution of an Unverified Python Gate
- Content
View full analysis
Vulnerability Details
File Location:
scripts/run_byte_gate.py:17-26
Vulnerability Type: Unverified external code execution through an environment-controlled path
Risk Level: HighVulnerable Code
python def stack_gate(path: Path) -> int: stack = os.environ.get("LYGO_STACK_ROOT", "").strip() if not stack: return -1 gate = Path(stack) / ".grok" / "skills" / "lygo-protocol-stack-operator" / "scripts" / "lygo_p0_gate.py" if not gate.is_file(): gate = Path(stack) / "clawhub" / "mirrors" / "lygo-protocol-stack-operator" / "scripts" / "lygo_p0_gate.py" if not gate.is_file(): return -1 return subprocess.call([sys.executable, str(gate), str(path)])Technical Analysis
The script obtains
LYGO_STACK_ROOTfrom the process environment and constructs one of two expected paths beneath it. If a regular file exists at either location, the file is executed with the current Python interpreter.The existence checks do not establish that the selected file belongs to the expected project or is trustworthy. The code does not validate the resolved root against an approved path, check ownership or permissions, verify a cryptographic hash or signature, or require confirmation before executing the discovered script.
Using an argument array prevents shell-metacharacter injection, but it does not address executable substitution: an attacker who can influence the environment and populate the expected directory structure can select arbitrary Python code for execution.
Attack Path
- An attacker gains control over the
LYGO_STACK_ROOTenvironment value or causes the command to run in an environment containing an attacker-selected value. - The attacker creates either expected nested path beneath that root:
.grok/skills/lygo-protocol-stack-operator/scripts/lygo_p0_gate.py, orclawhub/mirrors/lygo-protocol-stack-operator/scripts/lygo_p0_gate.py.
- The attacker places arbitrary Python code ...[truncated 920 chars]
- An attacker gains control over the
- Remediation
View remediation
Remediation Suggestions
- Do not discover executable code solely through an environment variable. Prefer a pinned, packaged implementation imported through the normal dependency mechanism.
- Require the external integration to be explicitly enabled and display the fully resolved executable path before running it.
- Resolve the path with
Path.resolve()and ensure it is beneath a user-approved canonical root. - Verify the external file using a pinned cryptographic digest or a trusted digital signature before execution.
- Validate file ownership and reject files or parent directories writable by untrusted users.
- Consider running the external gate in a sandbox with minimal filesystem, environment, and network access.
- Fail closed with a clear review-required result if authenticity cannot be established; do not silently treat path existence as proof of identity.
- Add tests proving that arbitrary roots and modified gate files are rejected.
