T09 · Insecure Skill Coding Practices
- Location
scripts/hot_scanner.py:22- Finding
Entire process environment exposed to a network-capable third-party CLI
- Content
View full analysis
Vulnerability Details
File Location:
scripts/hot_scanner.py:22-30, 387-392;scripts/rumor_scanner.py:30-38, 75-81, 128-134
Vulnerability Type: Excessive environment disclosure across a subprocess trust boundary
Risk Level: HighVulnerable Code
scripts/hot_scanner.py:22-30:python # Load .env file if exists ENV_FILE = Path(__file__).parent.parent / ".env" if ENV_FILE.exists(): with open(ENV_FILE) as f: for line in f: line = line.strip() if line and not line.startswith("#") and "=" in line: key, value = line.split("=", 1) os.environ[key] = valuescripts/hot_scanner.py:387-392:python env = os.environ.copy() result = subprocess.run( [bird_bin, "search", query, "-n", "15", "--json"], capture_output=True, text=True, timeout=30, env=env )scripts/rumor_scanner.py:30-38:python BIRD_ENV = Path(__file__).parent.parent / ".env" def load_env(): """Load environment variables from .env file.""" if BIRD_ENV.exists(): for line in BIRD_ENV.read_text().splitlines(): if '=' in line and not line.startswith('#'): key, value = line.split('=', 1) os.environ[key.strip()] = value.strip().strip('"').strip("'")scripts/rumor_scanner.py:75-81:python try: cmd = [BIRD_CLI, 'search', query, '-n', '10', '--json'] env = os.environ.copy() result = subprocess.run(cmd, capture_output=True, text=True, timeout=30, env=env)The same pattern is repeated for buzz searches at
scripts/rumor_scanner.py:128-134.Technical Analysis
The scanners parse every entry in the project-level
.envfile and insert it into the global process environment. They then copy and disclose the entire inherited environment to the separately installedbirdexecutable.The Twitter integration only requi ...[truncated 1493 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse only the explicitly required
AUTH_TOKENandCT0keys without modifying the globalos.environ. - Construct a minimal subprocess environment rather than using
os.environ.copy():python bird_env = { "PATH": trusted_path, "AUTH_TOKEN": auth_token, "CT0": ct0, } - Add only runtime variables demonstrably required by the CLI, such as a controlled
HOME, locale, or certificate path. - Reject unknown keys in the scanner-specific credential file.
- Resolve
birdto a configured, trusted absolute path and verify that the executable is not writable by untrusted users. - Run the CLI in a constrained environment or sandbox with restricted filesystem and network access.
- Avoid retaining Twitter credentials in the Python process after the subprocess finishes.
- Parse only the explicitly required
