T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:97- Finding
Global Command Hijacking Through Forced External Symlink
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 97-103
Vulnerability Type: Tool hijacking through replacement of a globally accessible command
Risk Level: HighVulnerable Code
bash A `nest` CLI helper is included at `scripts/nest`: # Make it available globally ln -sf /Users/mitchellbernstein/clawd/skills/google-home/scripts/nest /usr/local/bin/nest # List devices nest listTechnical Analysis
The documentation instructs the user to force-create the global
/usr/local/bin/nestsymlink using a hard-coded source path outside the audited project. The-foption can replace an existing file or symlink at the destination.The project contains only
SKILL.md; the claimedscripts/nesthelper is not included. Consequently, the executable installed under the legitimate-lookingnestcommand cannot be audited as part of this package. If another party can create or modify the hard-coded source path, subsequentnestinvocations will execute that party's code.This creates a local tool-hijacking primitive and violates least-privilege principles by modifying a global executable directory when a project-local invocation would be sufficient.
Attack Path
- An attacker gains write access to, or pre-creates,
/Users/mitchellbernstein/clawd/skills/google-home/scripts/nest. - The attacker places a malicious executable at that location.
- The user follows the documentation and runs the forced symlink command, with elevated permissions if required by the system.
/usr/local/bin/nestis created or an existing command at that path is replaced.- The user or another process invokes
nest, believing it to be the documented Google Home helper. - The attacker's executable runs with the privileges and environment of the invoking user.
Impact Assessment
Successful exploitation permits arbitrary command execution with the privileges of any user who invokes the hijacked comm ...[truncated 313 chars]
- An attacker gains write access to, or pre-creates,
- Remediation
View remediation
Remediation Suggestions
- Include the referenced helper inside the audited package rather than referring to an external, user-specific path.
- Resolve the helper path relative to the skill directory and verify that the resolved file remains inside the package.
- Do not use
ln -sfagainst global executable directories. - Prefer direct project-local execution or installation into a user-controlled directory such as
~/.local/bin. - Before installation, check whether the destination already exists and require explicit user confirmation rather than replacing it.
- Verify the helper's ownership, permissions, integrity, and expected checksum before installation or execution.
- Clearly display any operation requiring elevated privileges and avoid requesting those privileges unless strictly necessary.
