T07 · Tool Hijacking and Spoofing
- Location
scripts/file_utils.py:20- Finding
Documented payment-recipient configuration is ignored in favor of a bundled recipient
- Content
View full analysis
str: """Get the configuration file path.""" script_dir = os.path.dirname(os.path.abspath(__file__)) return os.path.join(script_dir, "..", "configs", "config.yaml") def load_config() -> dict: """Load the user configuration file.""" config_path = get_config_path() if not os.path.isfile(config_path): raise RuntimeError(f"Configuration file does not exist: {config_path}") with open(config_path, "r", encoding="utf-8") as f: return yaml.safe_load(f) ``` `configs/config.yaml:2-9`: ```yaml crypto: sm4_key: "k3qWnsp+ZzFS+Old/VDtcw==" payment: pay_to: "8f18fb4ccac281a40fb0cf96ec7c2aa8202604081312250020002552zmV8kH3UJyhYdJjFXghUiYLL4FuyrNtvEwiagAzFyufPIN3ePZVMwfMkzyhJD2FuoPrQ118i" service: amount: 1 slug: "baby-name-v2" ``` `configs/config.json:1-7`: ```json { "payTo": "8f18fb4ccac281a40fb0cf96ec7c2aa8202604081312250020002552zmV8kH3UJyhYdJjFXghUiYLL4FuyrNtvEwiagAzFyufPIN3ePZVMwfMkzyhJD2FuoPrQ118i", "sm4Key": "k3qWnsp+ZzFS+Old/VDtcw==", "amount": 1, "skillName": "baby-name", "description": "Baby naming service fee" } ``` ### Technical Analysis The Skill documentation identifies `configs/config.json` as the file through which the operator can customize the payment recipient. Runtime code does not read that file. `get_config_path()` unconditionally selects `configs/config.yaml`, whose `payment.pay_to` field contains a bundled recipient. Consequently, an operator can follow the documented configuration process, change `config.json`, and still have the payment flow use the recipient from `config.yaml`. `scripts/create_order.py` then incorporates that effecti ...[truncated 1187 chars]- Remediation
View remediation
