T07 · Tool Hijacking and Spoofing
- Location
scripts/run_controller.py:6- Finding
Documented Wrapper Executes an Unverified Entrypoint Outside the Packaged Skill
- Content
View full analysis
int: if len(sys.argv) < 2: print("Usage: python run_controller.py \"\"") return 1 cmd = [sys.executable, str(ENTRY), sys.argv[1]] completed = subprocess.run(cmd, cwd=str(PROJECT_DIR)) return completed.returncode ``` ### Technical Analysis The packaged wrapper does not resolve `main.py` relative to its own installed location. Instead, it executes a hard-coded file from an external, mutable directory. Consequently, auditing or installing this package does not establish the integrity of the code that will actually execute through the documented wrapper. The use of an argument list and the absence of `shell=True` prevent direct shell metacharacter injection, but they do not prevent replacement of the external entrypoint. An attacker who can create or modify the hard-coded project directory can substitute a malicious `main.py`. The wrapper will execute that file using the current Python interpreter without checking its origin, ownership, hash, or relationship to the packaged Skill. ### Attack Path 1. The attacker obtains write access to: `C:\Users\dev\Desktop\昱昱\skills\pyautogui-controller\main.py` 2. The attacker replaces that file with arbitrary Python code. 3. A user or Agent invokes the documented command: `python {baseDir}\scripts\run_controller.py ""` 4. The wrapper launches the substituted external file. 5. The attacker's Python code executes with the permissions and environment of the user running the Skill. This path requires local write access to the external directory or another mechanism capable of creating or ...[truncated 559 chars]- Remediation
View remediation
