T09 · Insecure Skill Coding Practices
- Location
scripts/run-lx-agent-cli.sh:4- Finding
Untrusted External Repository Code Execution Through Configurable Root Path
- Content
View full analysis
Vulnerability Details
File Location:
scripts/run-lx-agent-cli.sh:4-21
Vulnerability Type: Execution of unverified external repository code
Risk Level: HighVulnerable Code
bash ROOT_DIR="${LX_AGENT_ROOT:-$(pwd)}" if [[ $# -lt 1 ]]; then echo "Usage: run-lx-agent-cli.sh <command> [args...]" >&2 echo "Example: run-lx-agent-cli.sh config" >&2 exit 2 fi if [[ ! -f "$ROOT_DIR/go.mod" || ! -d "$ROOT_DIR/cmd/lx-agent" ]]; then echo "LX_AGENT_ROOT does not look like an lx-agent repo: $ROOT_DIR" >&2 exit 1 fi cmd="$1" shift || true cd "$ROOT_DIR" go run ./cmd/lx-agent "$cmd" "$@"Technical Analysis
The bridge accepts an arbitrary directory through
LX_AGENT_ROOT, falling back to the current working directory. It validates only that the selected directory contains ago.modfile and acmd/lx-agentdirectory. These name-based checks do not establish the repository's identity, ownership, integrity, or trusted revision.The subsequent
go run ./cmd/lx-agentcommand compiles and executes code from that unverified directory with the bridge process's privileges. A malicious repository can therefore execute arbitrary Go program logic. Depending on the module configuration and local Go environment,go runcan also resolve and download dependencies specified by an attacker-controlledgo.mod, introducing an additional supply-chain and network-execution surface.This audit cannot verify the intended
lx-agentimplementation because its source code is not included in the project. Consequently, the CLI's authentication handling, configuration output, network destinations, andbotorservebehavior remain outside the audited trust boundary.Attack Path
- An attacker gains control over the
LX_AGENT_ROOTenvironment variable, the process's working directory, or a directory expected to contain thelx-agentrepository. - The attacker creates a
go.modfile an ...[truncated 1329 chars]
- An attacker gains control over the
- Remediation
View remediation
Remediation Suggestions
- Replace the caller-controlled repository root with a fixed, canonical path managed by the Skill or administrator.
- If configurability is necessary, canonicalize the path and enforce an allowlist of approved repository locations.
- Verify repository provenance and integrity before execution, such as by checking a pinned commit and cryptographic artifact digest.
- Reject repositories or executable source trees writable by untrusted users.
- Build the reviewed CLI ahead of time and invoke a pinned binary instead of using
go runat runtime. - Use vendored or checksum-locked dependencies and disable unexpected network dependency resolution during execution.
- Run the CLI with a restricted service account, minimal filesystem permissions, a sanitized environment, and constrained network access.
- Ensure diagnostic commands never print token values, particularly because
SKILL.mdrequires invoking theconfigcommand during verification.
