T09 · Insecure Skill Coding Practices
- Location
create_rustchain_agent/__main__.py:47- Finding
Arbitrary Python Code Injection Through Generated Agent Source
- Content
View full analysis
Vulnerability Details
File Location:
create_rustchain_agent/__main__.py, lines 47-59 and 141-144
Vulnerability Type: Improper neutralization of user-controlled input during source-code generation
Risk Level: HighVulnerable Code
python AGENT_PY = '''#!/usr/bin/env python3 """{name} — a RustChain-participating agent (scaffolded by create-rustchain-agent). First run: checks the node is reachable, prints your RTC address + balance, and shows how to claim the First-Light newcomer bounty so your wallet is funded. """ import json, os, urllib.request NODE_URL = "{node}" WALLET = os.path.join(os.path.dirname(__file__), "wallet.json")The user-controlled values are inserted into the template here:
python with open(os.path.join(name, "agent.py"), "w") as f: f.write(AGENT_PY.format(name=name, node=node_url))The values originate from command-line arguments:
python p.add_argument("name", help="project/agent directory name to create") p.add_argument("--node", default=NODE_URL, help=f"node URL (default {NODE_URL})")Technical Analysis
The
nameand--nodearguments are placed directly into executable Python source usingstr.format(). They are not validated or encoded as Python string literals.A malicious
--nodevalue can terminate theNODE_URLstring, insert Python statements, and comment out the remaining content. Similarly, a crafted project name can terminate the generated module docstring by supplying triple quotes and inject statements into the generated file.This is a source-code injection vulnerability rather than immediate command injection during scaffolding. The injected code executes when the user follows the documented instruction to run:
bash cd <generated-directory> && python agent.pyFor example, a malicious node argument can conceptually use a structure such as:
text "; __import__("os").system(" ...[truncated 1623 chars]- Remediation
View remediation
Remediation Suggestions
-
Never interpolate untrusted input directly into executable source-code strings.
-
Encode values as valid Python literals before inserting them. For example:
python safe_node = repr(node_url)The template should use the already encoded literal without surrounding it with an additional pair of quotes.
-
Prefer generating a static
agent.pythat reads non-executable configuration from a JSON or TOML file. Writenode_urlwithjson.dump()rather than embedding it in Python source. -
Restrict project names to a conservative allowlist such as letters, digits, underscores, periods, and hyphens. Reject path separators, control characters, quotes, and newline characters.
-
Parse and validate
--nodewithurllib.parse.urlparse(). Permit only explicitly supported schemes, normally HTTPS, and reject control characters. -
Add regression tests covering single and double quotes, triple quotes, backslashes, braces, carriage returns, newlines, and comment characters.
-
After generation, compile
agent.pyin a non-executing validation step, such asast.parse(), while recognizing that syntax validation is only defense in depth and does not replace safe encoding.
-
