T07 · Tool Hijacking and Spoofing
- Location
scripts/hooks.py:18- Finding
Automatic Execution of Repository-Controlled Lifecycle Hooks
- Content
View full analysis
list[Path]: """Discover .spex.toml files in priority order (highest first).""" config_file = _spex_config_file_override or os.environ.get("SPEX_CONFIG_FILE") if config_file: p = Path(config_file).expanduser().resolve() if not p.is_file(): raise FileNotFoundError( f"Specified spex config file does not exist: {config_file}" ) return [p] candidates: list[Path] = [] visited: set[Path] = set() if main_worktree is not None: start = main_worktree.resolve() else: start = Path(workdir).resolve() if workdir else Path.cwd().resolve() current = start while True: toml_path = current / ".spex.toml" if toml_path.is_file(): candidates.append(toml_path) visited.add(toml_path.resolve()) parent = current.parent if parent == current: break current = parent ``` ```python # scripts/common.py:318-324 def _resolve_hook_roots(workdir=None): """Return hook root paths in priority order (highest first). Builds from all resolved spex_roots: /hooks/ for each. """ ctx = get_project_context(workdir) return [Path(sr) / "hooks" for sr in ctx.spex_roots] ``` ```python # scripts/hooks.py:18-30 def find_hook(hook_name: str, workdir=None) -> Path | None: """Find the first executable hook file in priority order.""" for root in _resolve_hook_roots(workdir): candidate = root / hook_name if candidate.is_file() and os.access(candidate ...[truncated 3454 chars]- Remediation
View remediation
