T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/workflow_core.py:64- Finding
Overbroad Environment File Discovery Crosses Project Trust Boundaries
- Content
View full analysis
Path | None: """Load the first discovered .env file from common locations.""" script_dir = Path(__file__).resolve().parent candidates: list[Path] = [ Path.cwd() / ".env", script_dir / ".env", plan_path.parent / ".env", ] candidates.extend(parent / ".env" for parent in plan_path.parent.parents) candidates.append(Path.home() / ".codex" / "skills" / "open-apple-style-ppt-maker" / ".env") seen: set[Path] = set() for candidate in candidates: candidate = candidate.resolve() if candidate in seen: continue seen.add(candidate) if candidate.exists(): load_dotenv(candidate, override=False) return candidate load_dotenv(override=False) return None ``` ### Technical Analysis The function searches for `.env` files in the current working directory, the script directory, the plan directory, and every ancestor of the plan directory up to the filesystem root. It then loads the first existing file into the process environment. This behavior exceeds the documented environment-file scope in `SKILL.md`, which only mentions the current directory and Skill directory. A plan located inside an unrelated project can therefore cause the Skill to read that project's `.env` file without explicit user approval. Although `override=False` prevents loaded values from replacing variables already present in the environment, it does not prevent previously unset secrets from being imported. The generation workflow subsequently obtains a Gemini credential from the resulting environment: ```python def get_api_key() -> str: key = os.getenv("APPLE_STYLE_PPT_MAKER_GEMINI_API_KEY") or os.getenv("GEMINI_API_KEY") ...[truncated 1891 chars]- Remediation
View remediation
