T09 · Insecure Skill Coding Practices
- Location
examples/tools_example.py:25- Finding
Arbitrary Code Execution Through an Agent-Callable eval Function
- Content
View full analysis
Vulnerability Details
File Location:
examples/tools_example.py:25-33; the same unsafe pattern is recommended inSKILL.md:345-353
Vulnerability Type: Unrestricted evaluation of an Agent-controlled expression
Risk Level: HighVulnerable Code
examples/tools_example.py:25-33:python @function_tool def calculate(expression: Annotated[str, "数学表达式"]) -> float: """计算数学表达式的结果""" print(f"[调试] 计算: {expression}") try: result = eval(expression) return float(result) except Exception as e: return 0.0SKILL.md:345-353:python @function_tool def calculate( expression: Annotated[str, "数学表达式,如 '2+2' 或 'sqrt(16)'"] ) -> float: """ 计算数学表达式的结果。 支持基本运算、三角函数、对数等。 """ return eval(expression)Technical Analysis
Python's
eval()evaluates its argument as a Python expression in the current process. The implementation does not restrict available syntax, names, built-ins, attributes, or function calls. Becausecalculateis registered with@function_tool, an LLM can supply theexpressionargument based on user-controlled prompt content.An attacker could induce a call containing an expression such as:
python __import__("os").system("id")More complex expressions could read local files, inspect environment variables, create or modify files, initiate network connections, or launch additional processes. Converting the result to
floatdoes not provide protection because side effects occur whileeval()is executing. Likewise, the exception handler only catches errors after potentially malicious operations have already occurred.The documentation reproduces the vulnerable implementation as a recommended tool-development practice, increasing the likelihood that users will copy it into other Agent applications.
Attack Path
- A user submits a prompt designed to make the Agent perform ...[truncated 1377 chars]
- Remediation
View remediation
Remediation Suggestions
Remove all uses of
eval()from Agent-callable tools and documentation.- Use a dedicated arithmetic-expression parser that supports only the required numeric operations.
- Alternatively, parse input with
ast.parse(..., mode="eval")and recursively evaluate only an explicit allowlist of nodes, such as numeric constants, unary arithmetic operators, and approved binary arithmetic operators. - Reject names, attribute access, function calls, comprehensions, imports, subscripting, lambdas, and all other unsupported syntax.
- Enforce limits on expression length, numeric magnitude, nesting depth, and computation complexity to prevent resource exhaustion.
- Return a clear validation error instead of suppressing all exceptions and returning
0.0. - Add tests containing malicious expressions such as imports, attribute traversal, function calls, and oversized exponentiation.
- Replace the unsafe example in
SKILL.mdso users are not encouraged to copy the vulnerability. - Run Agent tools in a least-privileged, isolated environment without unnecessary filesystem, credential, or network access as defense in depth.
