T05 · Unauthorized Access and Privilege Escalation
- Location
env-manager.js:63- Finding
Environment Variable Permits Writes Outside the Declared Workspace
- Content
View full analysis
Vulnerability Details
File Location:
env-manager.js:63-75
Vulnerability Type: Workspace boundary bypass through runtime path redirection
Risk Level: HighVulnerable Code
js // Resolution order: // 1. ENV_MANAGER_WORKSPACE env var (explicit override, must be absolute) // 2. Otherwise: the project root that contains this skill — i.e. the // grandparent of this file's directory (skills/env-manager/ -> repo root). // This is fixed and does not search upward beyond two levels. function getWorkspace() { if (process.env.ENV_MANAGER_WORKSPACE) { const o = path.resolve(process.env.ENV_MANAGER_WORKSPACE); if (!path.isAbsolute(o)) { throw new Error('ENV_MANAGER_WORKSPACE must be an absolute path'); } return o; } // Fixed: two levels up from this file — no upward walk. return path.resolve(__dirname, '..', '..'); }Technical Analysis
The workspace root is taken from the process-controlled
ENV_MANAGER_WORKSPACEenvironment variable. This value controls the base directory used for project scaffolding underenvironments/and state storage undermemory/environments/.The absolute-path validation is ineffective because
path.resolve()converts both relative and absolute input into an absolute path beforepath.isAbsolute()is called. Consequently, any non-empty override accepted bypath.resolve()passes the check.This behavior contradicts the trust model stated in
SKILL.md,README.md, andSECURITY-AUDIT.md, which says that runtime path redirection is not supported and that writes remain inside the Agent workspace. The override is also unnecessary for the minimum privileges required by a workspace-scaffolding Skill.Attack Path
- An attacker or untrusted launcher sets
ENV_MANAGER_WORKSPACEto a writable directory outside the intended Agent workspace. - The Skill is invoked through
setupEnvironment()or the `--setup ...[truncated 1071 chars]
- An attacker or untrusted launcher sets
- Remediation
View remediation
Remediation Suggestions
- Remove
ENV_MANAGER_WORKSPACEsupport and derive the workspace from an immutable, trusted configuration. - If an override is required, validate the original value before applying
path.resolve():js const raw = process.env.ENV_MANAGER_WORKSPACE; if (!path.isAbsolute(raw)) { throw new Error('ENV_MANAGER_WORKSPACE must be an absolute path'); } - Define a trusted root independently of attacker-controlled environment variables.
- Canonicalize both the trusted root and requested destination with
fs.realpathSync(). - Enforce containment using
path.relative()and reject results that are.., begin with../, or are absolute. - Update all trust-model documentation to accurately describe any retained override.
- Add tests covering relative overrides, absolute external paths, path normalization, and symbolic-link escapes.
- Remove
