T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/smoke_test.py:21- Finding
Smoke Test Bypasses the Explicit Retrieval Consent Requirement
- Content
View full analysis
int: ap = argparse.ArgumentParser() ap.add_argument("--stack-root", default=None) args = ap.parse_args() root_args = ["--stack-root", args.stack_root] if args.stack_root else [] steps = [ ("preflight.py", root_args), ("verify_eggs.py", root_args), # list requires consent after v1.3 SkillSpector harden ("retrieve_egg.py", ["--i-consent", "--list", *root_args]), ] for name, extra in steps: rc = run(name, extra) if rc != 0: print(f"smoke_test FAIL at {name} (exit {rc})", file=sys.stderr) return rc print("smoke_test: PASS") return 0 ``` ### Technical Analysis The retrieval wrapper requires affirmative user consent before listing or retrieving egg registry content. However, the smoke test unconditionally supplies `--i-consent` to `retrieve_egg.py` on the user's behalf. This is inconsistent with the consent model implemented in `scripts/_stack_paths.py`, under which consent must come from an explicit command-line flag or the `LYGO_EGG_PLANT_CONSENT` environment variable. It also contradicts the documented requirement that consent must never be inferred. Although `retrieve_egg.py` performs verification before access, integrity verification and authorization are separate controls. Successful verification does not establish that the user consented to registry access. The smoke test therefore converts an ordinary smoke-test invocation into an authorized retrieval-list operation without requiring the caller to provide the authorization signal. ### Attack Path 1. A valid LYGO stack is configured through `--stack-root`, `LYGO_STACK_ROOT`, or automatic stack-root discovery. 2. The user runs: ```bash python scripts/smoke_test.py ``` without ...[truncated 1154 chars]- Remediation
View remediation
