T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:29- Finding
Persistent Weakening of System Hosts File Ownership
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate GitHub connectivity purpose, but it uses unsafe system-level DNS changes and unvalidated shell execution that users should review before installing.
Install only if you are comfortable with a tool that can change system-wide DNS behavior. Do not run the documented chown commands as written; keep hosts-file ownership at the operating-system default. Avoid custom hosts URLs, review any proposed hosts entries before applying them, and prefer a version that validates hostnames/IPs and uses argument-array subprocess calls or native HTTP fetching instead of shell=True.
SKILL.md:29Persistent Weakening of System Hosts File Ownership
scripts/fix_github_dns.py:74Shell Command Injection Through Custom Hosts URL
scripts/fix_github_dns.py:81Untrusted Remote Hosts Data Written to System Name Resolution
run_command is a generic shell execution wrapper that accepts arbitrary command strings and optionally prepends sudo, creating an unnecessary execution primitive inside a DNS-fix utility. Because later code passes interpolated data into this wrapper, the function enables arbitrary shell command execution beyond the tool’s stated purpose.
Using subprocess.run(cmd, shell=True) turns tool parameters and internal variables into a shell-interpreted execution surface, enabling parameter abuse when any part of cmd is attacker controlled. In this skill, user-supplied URL parameters flow into command strings, so the risk is concrete rather than theoretical.
def run_command(cmd, sudo=False):
if sudo:
cmd = f"sudo {cmd}"
result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
return result.returncode, result.stdout, result.stderr
Custom hosts URLs supplied via -u/--urls are interpolated directly into curl -s --max-time 10 {url} and executed with shell=True, allowing an attacker to inject shell metacharacters and run arbitrary commands. This is especially dangerous because the script is intended to be run by users troubleshooting system networking and may be executed with administrative privileges to modify /etc/hosts or the Windows hosts file.
The skill invokes a local Python script and instructs the user to modify system files, which implies shell execution plus file read/write capability, yet it declares no tool scope or permission boundaries. In an agent environment, missing explicit tool restrictions increases the chance the skill can be run with broader-than-intended privileges and makes review/auditing harder.
The description and operating instructions are written entirely in Chinese and instruct the assistant in Chinese, with no indication that the user can choose another language. This can violate a language/locale policy when skills are expected to respect user language preference unless a locale restriction is explicitly documented and justified.
The skill instructs the user to run sudo chown on /etc/hosts, transferring ownership of a sensitive system file to the current user. Changing ownership of /etc/hosts weakens operating-system protections and can enable later unauthorized or accidental tampering with name resolution, which can redirect traffic to attacker-controlled destinations.
macOS:
sudo chown $(whoami):staff /etc/hosts
sudo chmod 644 /etc/hosts
The instruction to run sudo chmod 644 /etc/hosts as part of making the file user-managed is risky in context because it normalizes privileged modification of a critical configuration file and may leave it writable through the preceding ownership change. Combined with the ownership transfer, this reduces defense-in-depth around DNS resolution on the host.
macOS:
sudo chown $(whoami):staff /etc/hosts
sudo chmod 644 /etc/hosts
Linux:
The instruction to run sudo chmod 644 /etc/hosts as part of making the file user-managed is risky in context because it normalizes privileged modification of a critical configuration file and may leave it writable through the preceding ownership change. Combined with the ownership transfer, this reduces defense-in-depth around DNS resolution on the host.
macOS:
sudo chown $(whoami):staff /etc/hosts
sudo chmod 644 /etc/hosts
Linux:
The Linux instruction to sudo chown /etc/hosts to the current user permanently delegates control of a critical networking file to a non-system account. If that account or any process running as that user is compromised, attackers can hijack DNS resolution for GitHub or other domains, enabling phishing, traffic interception, or update redirection.
Linux:
sudo chown $(whoami):$(whoami) /etc/hosts
sudo chmod 644 /etc/hosts
The chmod command is not dangerous in isolation, but in this workflow it reinforces a persistent weakening of protections around /etc/hosts after ownership is changed. The more dangerous context is that the skill aims to make future edits possible without sudo, which removes an important friction/control point for altering system name resolution.
Linux:
sudo chown $(whoami):$(whoami) /etc/hosts
sudo chmod 644 /etc/hosts
Windows:
The chmod command is not dangerous in isolation, but in this workflow it reinforces a persistent weakening of protections around /etc/hosts after ownership is changed. The more dangerous context is that the skill aims to make future edits possible without sudo, which removes an important friction/control point for altering system name resolution.
Linux:
sudo chown $(whoami):$(whoami) /etc/hosts
sudo chmod 644 /etc/hosts
Windows:
Stating that after a one-time manual step the script can modify hosts entries without sudo indicates a design that intentionally bypasses normal privilege boundaries for a sensitive system file. In skill context, this is more dangerous because the whole purpose is to alter DNS resolution for GitHub, so any mistake or malicious update source could silently redirect developer traffic.
- 直接以管理员身份运行命令提示符或 PowerShell 即可
⚠️ **此操作必须由用户在系统终端中手动执行**
执行后,脚本将不再需要 sudo 权限,可以免密码运行
### 仅检查连接状态
The function can prepend sudo to shell commands, which increases the blast radius of any command injection or misuse in downstream callers. In this script, the combination of privilege escalation capability and shell-based command construction makes exploitation materially more dangerous because successful injection could execute as root or prompt users to authorize privileged actions.
def run_command(cmd, sudo=False):
if sudo:
cmd = f"sudo {cmd}"
result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
return result.returncode, result.stdout, result.stderr
The helper executes shell commands with subprocess.run(..., shell=True), which is dangerous because multiple call sites build cmd from variable input, including user-provided URLs. In this skill’s context, a GitHub DNS repair tool has no legitimate need to expose a shell-interpreted command surface, so command injection can lead to arbitrary code execution under the invoking user and potentially elevated privileges when sudo is prepended.
def run_command(cmd, sudo=False):
if sudo:
cmd = f"sudo {cmd}"
result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
return result.returncode, result.stdout, result.stderr
This code file contains natural-language strings for the command description and help text that force a specific language/locale. The policy for SQP-3 applies to all file types, and there is no opt-in, fallback, or documented justification for limiting the interface to Chinese.
No suspicious patterns detected.