T09 · Insecure Skill Coding Practices
- Location
integrations/framework_enhancements.py:332- Finding
Unrestricted In-Process Python Code Execution
- Content
View full analysis
Dict[str, Any]: result = { "agent": self.name, "code": code, "timestamp": datetime.now().isoformat(), "output": None, "error": None } try: local_vars = {} exec(code, {"__builtins__": __builtins__, **self.tools}, local_vars) ``` ### Technical Analysis The `execute_code` method passes caller-controlled Python source directly to `exec`. The execution context exposes the complete Python built-in namespace through `__builtins__`. Consequently, executed code can import modules, access the filesystem, inspect environment variables, create network connections, and start operating-system processes. Although the module describes this feature as code-agent or sandbox functionality, the implementation provides no process isolation, import restrictions, syscall filtering, filesystem boundary, network restriction, timeout, or resource limit. Exception handling only records errors after execution and does not constrain what the payload can do. This exceeds the minimum privilege required for generating or reviewing code. The dangerous method is a callable library entry point rather than an automatic startup path, but any untrusted, user-supplied, or model-generated input passed to it receives the full privileges of the host process. ### Attack Path 1. An attacker influences the `code` argument passed to `CodeAgent.execute_code`. 2. The supplied code imports modules such as `os`, `pathlib`, `socket`, or `subprocess`. 3. `exec` evaluates the payload with unrestricted built-ins. 4. The payload reads environment credentials or local files, modifies project or configuration files, launches commands, or opens outbound network connections. 5. ...[truncated 473 chars]- Remediation
View remediation
