T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:142- Finding
Unbundled Relative Executables May Resolve to Attacker-Controlled Tools
- Content
View full analysis
" --attachments "Attachments" # Output: orphan-attachments.csv, including file path, size, and modification time ``` ```bash # Move images to Attachments/Images/, PDFs to Attachments/PDF/ scripts/organize-attachments --vault "" \ --rule "image:Attachments/Images" \ --rule "pdf:Attachments/PDF" \ --rule "audio:Attachments/Audio" ``` ```bash # Delete attachments that have not been referenced for 90 days scripts/clean-orphans --vault "" --days 90 --dry-run scripts/clean-orphans --vault "" --days 90 ``` ```bash scripts/cross-vault-search "OKR" --vaults work,personal ``` ### Technical Analysis The Skill directs the Agent to execute several helpers through relative paths under `scripts/`. The audited project contains only `SKILL.md`; the referenced executables are not included, defined, version-pinned, or authenticated. Relative executable paths are resolved according to the process working directory rather than a trusted, canonical Skill installation directory. If the Agent runs from a directory containing an attacker-created `scripts/clean-orphans`, `scripts/orphan-scan`, `scripts/organize-attachments`, or `scripts/cross-vault-search`, that executable can be invoked as though it were a legitimate component of the Skill. The helpers receive vault locations and are expected to possess filesystem access. In particular, `clean-orphans` is represented as performing deletion, making substitution especially dangerous. The use of `--dry-run` does not establish a security boundary because a substituted executable can ignore that argument. ### Attack Path 1. An attacker gains the ability to place files in, or influence, the Agent's current ...[truncated 1118 chars]- Remediation
View remediation
