T01 · Skill Instruction Hijacking
- Location
scripts/clone_robot.py:266- Finding
Unrestricted Archive Import Allows Agent Instruction and Memory Poisoning
- Content
View full analysis
Vulnerability Details
File Location:
scripts/clone_robot.py:266-283andscripts/clone_robot.py:367-406
Vulnerability Type: Unrestricted archive member extraction into an agent workspace
Risk Level: HighVulnerable Code
python with zipfile.ZipFile(package_path, 'r') as zipf: for name in zipf.namelist(): # Check path safety if not is_path_safe(name): print(f" ❌ Unsafe path: {name}") return False # Check suspicious files if name.endswith(('.exe', '.bat', '.sh', '.cmd')): print(f" ⚠️ Suspicious file: {name}") # Check absolute paths if os.path.isabs(name): print(f" ❌ Absolute path: {name}") return False print(f" ✅ Security check passed") return Truepython # List files that will be copied print(f"\n📋 Files to be imported:") files_to_import = [] with zipfile.ZipFile(package, 'r') as zipf: for name in zipf.namelist(): if name != "clone_metadata.json": print(f" ✅ {name}") files_to_import.append(name) # Confirmation in non-force mode if not force: print(f"\n⚠️ Warning: Existing files in the target directory will be overwritten!") print(f" Use --force to skip confirmation") try: response = input("\nConfirm import? (y/N): ").strip().lower() if response not in ['y', 'yes']: print("❌ Import cancelled") return False except (EOFError, KeyboardInterrupt): print("\n❌ Import cancelled") return False # Extract files print(f"\n📥 Importing...") target.mkdir(parents=True, exist_ok=True) with zipfile.ZipFile(package, 'r') as zipf: for name in zipf.namelist(): if name == "clone_metadata.json": continue # Validate path again if not is_path_safe(name): prin ...[truncated 3133 chars]- Remediation
View remediation
Remediation Suggestions
- Define an explicit allowlist of permitted archive members, such as the documented core configuration filenames. Reject every unrecognized file rather than importing it.
- If optional subdirectories are supported in the future, define narrowly scoped permitted prefixes and acceptable file types for each directory.
- Reject executable and active-content extensions. A warning is insufficient.
- Require a manifest listing each authorized path, expected size, and cryptographic hash. Reject missing, additional, duplicate, or mismatched members.
- Authenticate packages with a trusted digital signature when packages are distributed between users or systems.
- Stage imported content in a secure temporary directory and present per-file diffs for instruction-bearing and persistent-state files.
- Back up existing files before replacement and perform rollback if any validation or write fails.
- Require explicit approval for replacing
AGENTS.md,SOUL.md,TOOLS.md,MEMORY.md, and other security-sensitive files, even when--forceis used. - Do not describe a package as safe merely because its paths are traversal-safe. Distinguish structural ZIP validation from content trust and package authenticity.
