T09 · Insecure Skill Coding Practices
- Location
SKILL.md:49- Finding
Arbitrary Python Code Execution Through Unsafe Filesystem Path Interpolation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 49-57
Vulnerability Type: Command injection through unsafe interpolation into Python source code
Risk Level: HighVulnerable Code
bash find / -path "*/node_modules/axios/package.json" 2>/dev/null | \ xargs -I{} python3 -c " import json d = json.load(open('{}')) v = d.get('version','?') flag = '❌ MALICIOUS' if v in ['1.14.1','0.30.4'] else '✅ safe' print(flag, v, '{}') " 2>/dev/nullTechnical Analysis
The
findoutput is substituted byxargs -I{}directly into a Python program passed throughpython3 -c. The discovered path is therefore interpreted as part of the Python source code rather than passed as an opaque command-line argument.A filesystem entry containing quote characters, line breaks, or crafted Python syntax can terminate the intended string literal and inject additional Python statements. Because the command scans the entire filesystem, including attacker-writable locations such as
/tmp, an unprivileged local attacker may be able to create a matching path that triggers the injection.The pipeline also fails to use null-delimited filenames. Paths containing whitespace, line breaks, or other unusual characters can consequently be parsed incorrectly even when they are not deliberately malicious.
Attack Path
- An attacker with permission to create directories in a scanned location creates a path matching
*/node_modules/axios/package.json. - One of the path components contains characters crafted to close the
open('...')string and append attacker-controlled Python code. - A user or Agent invokes the documented Axios scanning command.
find /discovers the attacker-controlled pathname.xargs -I{}inserts that pathname directly into the source supplied topython3 -c.- Python parses and executes the injected statements with the privileges of the user running the Skill.
Impact Ass
...[truncated 634 chars]
- An attacker with permission to create directories in a scanned location creates a path matching
- Remediation
View remediation
Remediation Suggestions
Pass each discovered path as a command-line argument rather than embedding it in Python source. Use null-delimited records to preserve filenames safely:
bash find / -path '*/node_modules/axios/package.json' -print0 2>/dev/null | xargs -0 -r -n1 python3 -c ' import json import sys path = sys.argv[1] with open(path, encoding="utf-8") as package_file: data = json.load(package_file) version = data.get("version", "?") status = "MALICIOUS" if version in {"1.14.1", "0.30.4"} else "safe" print(status, version, path) 'Additional hardening should include:
- Restrict searches to known npm installation and project directories instead of
/. - Avoid scanning attacker-writable temporary directories unless explicitly required.
- Handle malformed or oversized JSON files without suppressing all errors.
- Run the scan as an unprivileged account.
- Add regression tests using filenames containing quotes, newlines, spaces, and Python syntax.
- Restrict searches to known npm installation and project directories instead of
