T07 · Tool Hijacking and Spoofing
- Location
preload.py:5- Finding
Execution of Python Code Outside the Skill Package
- Content
View full analysis
1 else 'demo' if p.exists(): import runpy runpy.run_path(str(p), run_name='__main__') ``` ### Technical Analysis `preload.py` is located in the Skill package directory, but `Path(__file__).resolve().parents[1]` resolves to the parent of that directory. Consequently, the launcher does not execute the packaged `context_sim.py`; it searches for and executes a different file named `context_sim.py` outside the reviewed package. The file is executed through `runpy.run_path(..., run_name='__main__')`, which gives it normal Python code-execution capabilities under the privileges of the user running the Skill. There is no verification of the target file's ownership, integrity, origin, or containment within the package. This creates a local file-planting and tool-hijacking condition. The external file can impersonate the expected implementation while executing arbitrary attacker logic. ### Attack Path 1. An attacker obtains write access to the directory immediately above the Skill package. 2. The attacker places a malicious file named `context_sim.py` in that directory. 3. A user or automation invokes `python3 preload.py` as documented in `SKILL.md`. 4. `preload.py` resolves the attacker's file rather than the packaged implementation. 5. `runpy.run_path` executes the malicious file as `__main__`. 6. The payload runs with all filesystem, process, credential, and network permissions available to the invoking account. ### Impact Assessment Successful exploitation provides arbitrary Python code execution with the privileges of the account running the Skill. Depending on those privileges, an attacker could read or modify access ...[truncated 386 chars]- Remediation
View remediation
