T09 · Insecure Skill Coding Practices
- Location
scripts/ghx_generator.py:346- Finding
Unrestricted Executable GhPython Code Embedded in Generated GHX Files
- Content
View full analysis
ComponentRef: """Add a GhPython Script component with custom Python code. Code has access to input variables by name. Assign `a = result` for output. Full Rhino.Geometry API is available. """ inputs = inputs or [] outputs = outputs or [] if x is None: x = self._auto_x self._auto_x += 200 if y is None: y = 50 instance_guid = _new_guid() comp_guid = self._resolve_guid("GhPython Script") or _new_guid() obj = _chunk("Object") obj.append(_wrap_items([ _item("GUID", comp_guid, "gh_guid", TC_GUID), _item("Name", "GhPython Script", "gh_string", TC_STRING), ])) container = _chunk("Container") container.append(_wrap_items([ _item("CodeInput", code, "gh_string", TC_STRING), _item("Description", "A Python script component", "gh_string", TC_STRING), _item("InstanceGuid", instance_guid, "gh_guid", TC_GUID), _item("Name", "GhPython Script", "gh_string", TC_STRING), _item("NickName", nickname, "gh_string", TC_STRING), ])) ``` ### Technical Analysis The `add_python` method accepts arbitrary caller-provided Python source in the `code` argument and inserts it directly into the `CodeInput` field of a GhPython component. No validation, import restrictions, API allowlist, static analysis, or user-approval boundary is applied. Embedding custom scripts is an advertised feature, but the implementation does not limit scripts to geometry operations. A generated GHX file is therefore an executable documen ...[truncated 1599 chars]- Remediation
View remediation
