T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:52- Finding
Ambiguous Script Discovery Can Execute a Spoofed Skill Tool
- Content
View full analysis
/dev/null | head -1)")" python "$SKILL_DIR/smart_extract.py" "你的视频路径.mp4" "视频名_frames/" 15 ``` ### Technical Analysis The documented workflow recursively searches the entire shared `~/.workbuddy/skills` directory for any file named `smart_extract.py` and executes the first result. The selected file is not verified as belonging to this Skill, and the discovery order produced by `find` is not a security boundary. The audited script is packaged at `references/smart_extract.py`, but the command does not resolve that known package-relative path. Consequently, another installed Skill or a local process with write access to the shared skills directory could place a different file with the same name in a directory returned earlier by `find`. Because the selected file is passed directly to the Python interpreter, a spoofed script would execute arbitrary Python code with the permissions of the user or agent running the workflow. ### Attack Path 1. An attacker obtains the ability to install another Skill or write a file under `~/.workbuddy/skills`. 2. The attacker creates a malicious file named `smart_extract.py` in a location likely to be returned before the legitimate script. 3. A user invokes the documented video-analysis workflow. 4. The `find` command discovers both legitimate and attacker-controlled files. 5. `head -1` selects the first result without checking its package ownership or canonical path. 6. Python executes the attacker-controlled script under the agent's current account. ### Impact Assessment Successful exploitation permits arbitrary local code execution with the same privileges as the agent process. The malicious script could read or modify files accessible to that account, alter generat ...[truncated 288 chars]- Remediation
View remediation
