T09 · Insecure Skill Coding Practices
- Location
scripts/auto-debug.js:226- Finding
Arbitrary Project-Script Execution During Optional Build Verification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/auto-debug.js, lines 226–235
Vulnerability Type: Execution of untrusted project build scripts without isolation
Risk Level: HighVulnerable Code
js const pkg = JSON.parse(fs.readFileSync(pkgPath, 'utf8')); if (!pkg.scripts?.build) return; this.log('Running build check...'); const result = spawnSync('npm', ['run', 'build'], { cwd: this.projectDir, encoding: 'utf8', timeout: 120000, stdio: ['pipe', 'pipe', 'pipe'] });Technical Analysis
When the documented
--buildoption is enabled, the scanner reads the target project'spackage.jsonand invokesnpm run build. The build command itself is defined by the scanned project and must therefore be treated as untrusted.Although
spawnSyncuses a fixed executable and argument array, preventing direct shell injection throughprojectDir, it deliberately delegates execution to an attacker-controlled npm script. That script can contain arbitrary commands. The child process is not sandboxed, assigned reduced privileges, restricted to an allowlisted filesystem, or denied network access. The 120-second timeout only limits execution duration; it does not constrain the operations performed before termination.Optional build verification is part of the Skill's declared functionality, but unrestricted execution with the invoking user's full permissions exceeds the minimum privileges required for static source analysis. No direct HTTP client, socket, upload, or other network-exfiltration implementation was found in the reviewed Skill itself. However, a malicious build script can independently establish network connections and exfiltrate information.
Attack Path
-
An attacker creates or modifies a scanned Node.js project.
-
The attacker defines a malicious
scripts.buildentry in that project'spackage.json. -
A user or Agent runs:
bash node scripts/auto-debug.js /path/to/untrusted-project --build -
The s ...[truncated 1326 chars]
-
- Remediation
View remediation
Remediation Suggestions
- Keep static analysis as the default and clearly classify build verification as execution of untrusted project code.
- Before execution, display the exact
scripts.buildvalue and require explicit, informed user approval rather than relying only on the presence of--build. - Execute builds in a disposable sandbox or container configured with:
- A non-root, dedicated user.
- A read-only source mount where feasible.
- A separate writable build-output directory.
- No access to the host home directory, SSH agent, cloud metadata service, or credential stores.
- A minimal, scrubbed environment without tokens or secrets.
- Network access disabled by default or restricted to an explicit allowlist.
- CPU, memory, process-count, file-size, and execution-time limits.
- Avoid exposing sensitive host paths, sockets, or environment variables to the build process.
- Warn that npm lifecycle hooks and build-time dependencies can execute code, even when the visible build script appears benign.
- If secure isolation is unavailable, omit automated build execution and report the build command for the user to run manually in an appropriately isolated environment.
