T07 · Tool Hijacking and Spoofing
- Location
scripts/entry.py:16- Finding
External Import Path Allows Local Module Hijacking
- Content
View full analysis
/src/histrategy_agent` to override an otherwise legitimate installed dependency. The imported package is not included in the audited project and no ownership, integrity, signature, or permission checks are performed before loading it. Python executes module-level code during import, so a spoofed module can execute before normal message processing begins. Exploitation requires the attacker to be able to place files in the calculated adjacent `src` directory. This may be possible where multiple packages, users, deployment jobs, or extraction processes share a writable parent directory. ### Attack Path 1. The attacker obtains write access to the adjacent `/src` directory. 2. The attacker creates a spoofed package such as: `src/histrategy_agent/format_engine.py`. 3. The Skill starts and inserts that directory at index zero of `sys.path`. 4. Python resolves `histrategy_agent` from the attacker-controlled directory. 5. Malicious module-level code executes with the privileges of the Agent process. 6. The malicious package can then intercept incoming messages, manipulate responses, ins ...[truncated 654 chars]- Remediation
View remediation
