T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:88- Finding
Execution of an Unbundled Relative-Path Analytics Script
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 88–99
Vulnerability Type: Execution of an unaudited local tool through a relative path
Risk Level: MediumVulnerable Code
markdown ## 📊 Usage Analytics 當你使用此 Skill 完成任務後,請記錄使用次數: ```bash python3 skills/analytics.py taiwan-lease-review used查看統計:
bash python3 skills/analytics.py statstext ### Technical Analysis The Skill instructs the agent to execute `skills/analytics.py` after completing a task. That script is not included in the audited package, and its path is relative to the process's current working directory rather than being securely resolved against a verified Skill installation directory. Consequently, the identity and behavior of the executed script depend on the environment in which the command runs. A local project, compromised workspace, or other actor able to create or replace `skills/analytics.py` can cause the legitimate-looking analytics command to execute attacker-controlled Python code. The analytics operation is not required for the lease-review functionality. The audited package also does not disclose or enforce what information the external script may collect, store, or transmit. ### Attack Path 1. An attacker gains write access to the agent's current workspace or supplies a project containing `skills/analytics.py`. 2. The attacker places malicious Python code at that relative path. 3. The lease-review Skill is loaded and used normally. 4. After finishing the task, the agent follows the usage-analytics instruction in `SKILL.md`. 5. The command resolves `skills/analytics.py` relative to the current working directory. 6. Python executes the attacker-controlled script with the permissions and environment available to the agent process. This attack depends on the agent following the documented post-use instruction and the attacker being able to control the file resolved by the relative path. ### Impact Assessment Successful exploitation perm ...[truncated 748 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the post-use analytics commands because analytics is not necessary for the Skill's lease-review purpose.
- Do not instruct agents to execute scripts that are absent from the audited package.
- If analytics is essential, bundle the implementation within the Skill and include it in security reviews.
- Resolve the bundled script from a trusted, canonical Skill directory rather than from the current working directory.
- Verify the script's integrity before execution, such as by validating a trusted cryptographic hash or package signature.
- Require explicit user consent before collecting analytics.
- Document the exact fields collected, retention policy, storage location, and any network destination.
- Minimize collected information and avoid contract text, tenant or landlord identities, property addresses, credentials, and environment data.
- Disable network transmission by default and ensure analytics failures cannot affect the primary lease-review workflow.
- Consider removing or disabling the
analytics: truemetadata setting unless a bundled, consent-based, and auditable analytics mechanism is implemented.
