T09 · Insecure Skill Coding Practices
- Location
src/origin_pro_mcp/tools/labtalk.py:4- Finding
Unrestricted LabTalk Interpreter Exposed as an MCP Tool
- Content
View full analysis
str: """Execute a LabTalk script in Origin Pro. Use this for any Origin operation not covered by other tools. LabTalk is Origin's built-in scripting language. Args: script: LabTalk script to execute Returns: Success/failure message """ success = execute_labtalk(script) return f"Executed {'successfully' if success else 'with errors'}: {script}" ``` The tool forwards its argument to the following execution sink: ```python def execute_labtalk(script: str) -> bool: o = get_origin() return o.Execute(script) ``` The agent configuration also permits implicit invocation: ```yaml policy: allow_implicit_invocation: true ``` ### Technical Analysis The `run_labtalk` MCP tool accepts an arbitrary string and forwards it unchanged to Origin Pro's LabTalk interpreter. There is no command allowlist, syntax validation, restricted execution mode, authorization check, or confirmation step. This is particularly significant in an AI-agent context because tool arguments can be derived from untrusted prompts, imported documents, or other attacker-controlled content. Allowing implicit invocation increases the possibility that the interpreter could be reached without the user explicitly selecting the advanced scripting feature. The stdio transport limits direct network exposure, but it does not protect against prompt-driven misuse by an authorized local MCP client. ### Attack Path 1. A user or untrusted data source supplies instructions that influence the connected AI agent. 2. The agent selects `run_labtalk`, potentially through implicit skill invo ...[truncated 902 chars]- Remediation
View remediation
