T09 · Insecure Skill Coding Practices
- Location
recorder_server.py:944- Finding
Arbitrary Python execution in the recorder process
- Content
View full analysis
", "exec") exec(compiled, ns) ``` The execution path is exposed through the recorder action: ```python elif action == "python_snippet": raw_code = (data.get("code") or "").rstrip() if not raw_code.strip(): error = "python_snippet requires a non-empty 'code' field" else: error = await _python_snippet_run(raw_code, page) if not error: if "page.evaluate" in raw_code: global _SESSION_HAS_PAGE_EVALUATE _SESSION_HAS_PAGE_EVALUATE = True error = _check_snippet_reads_extract_files(raw_code) if not error: code_block = _step_code(step_n, context, raw_code.splitlines()) ``` ### Technical Analysis The recorder compiles and executes supplied Python inside its own process. The execution namespace does not remove or replace `__builtins__`. Python therefore makes standard built-ins available, including `__import__`, `open`, `eval`, and `exec`. Restricting the methods of the Playwright `page` object does not restrict Python itself. A snippet can import `os`, `subprocess`, `socket`, or HTTP libraries; read arbitrary files accessible to the recorder account; modify files; start processes; and communicate with arbitrary network services. The post-execution structural check does not provide preventive isolation. It runs only after the snippet has already executed, so rejecting the snippet at that stage cannot reverse its side effects. ### Attack Path 1. An attacker places prompt-injection content on a website or influences the task instructions processed by the agent. 2. The content induces the agent to submit a `python_snippet` action containing at ...[truncated 972 chars]- Remediation
View remediation
