T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:19- Finding
Mandatory Execution of an Unverified External Script
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 3 and 19-31; reinforced at lines 48-49
Vulnerability Type: Execution of a replaceable local tool outside the reviewed skill package
Risk Level: HighVulnerable Code
markdown ## CRITICAL RULE — NO FABRICATION **You MUST actually execute the Python command using your shell/exec tool.** Read the real output. NEVER generate fake advisor analyses, fake synthesis, or simulated council responses. If the script fails, report the actual error to Boss Man.markdown ## Run Full Advisory Council (All Assets) Fetches live prices for BTC, ETH, XRP, SUI and runs all 5 advisors + synthesis. ```bash cd ~/clawd && python3 advisory_council.pyRun Focused on a Specific Coin
Runs the full council but focuses analysis on one asset.
bash cd ~/clawd && python3 advisory_council.py SUIbash cd ~/clawd && python3 advisory_council.py BTCtext ```markdown ## Rules - **EXECUTE THE PYTHON COMMAND FOR REAL** — use your shell/exec tool. Never simulate council output.Technical Analysis
The skill unconditionally directs the agent to execute
advisory_council.pyfrom~/clawd, which is outside the reviewed project. The audited project contains onlySKILL.md; it does not contain the referenced Python script, a cryptographic digest, an ownership requirement, a trusted installation process, or any other mechanism for validating the executable before use.The command first changes into a user-writable directory and then resolves the script by its relative filename. Therefore, the effective behavior of the skill depends entirely on whatever file is present at
~/clawd/advisory_council.pywhen the command is executed. A process or user capable of creating or replacing that file can cause a legitimate-looking council request to execute attacker-controlled Python code.The documented claims that the script only retrieves live prices, invokes five advisors, and formats a report ca ...[truncated 1707 chars]
- Remediation
View remediation
Remediation Suggestions
- Package
advisory_council.pyinside the reviewed skill artifact so its implementation can be audited together withSKILL.md. - Invoke the script through a fixed, package-relative path rather than changing into
~/clawdand resolving a user-controlled relative filename. - Before execution, resolve the canonical path and reject symbolic links or paths that escape the expected package directory.
- Restrict ownership and write permissions so untrusted users and unrelated processes cannot replace the script.
- If an external deployment is unavoidable, verify a pinned cryptographic hash or authenticated signature immediately before each execution. Fail closed if validation fails.
- Run the script with least privilege in a sandbox that limits filesystem access, environment variables, subprocess execution, and outbound network destinations.
- Provide only the API credentials required for the documented functionality; do not expose unrelated secrets to the process.
- Remove the unconditional execution requirement. The agent should refuse execution when the script is missing, unverifiable, unexpectedly writable, or fails integrity checks.
- Document the script's expected network endpoints and dependencies, and include its dependency lockfile in the review scope.
- Package
