T07 · Tool Hijacking and Spoofing
- Location
scripts/render_alert_text.py:9- Finding
Relative Subprocess Path Can Execute an Attacker-Controlled Script
- Content
View full analysis
Vulnerability Details
File Location:
scripts/render_alert_text.py, lines 9–11
Vulnerability Type: Tool hijacking through unsafe relative-path resolution
Risk Level: MediumVulnerable Code
python import subprocess raw = subprocess.check_output( ['python3', 'skills/twitter-watch-reply/scripts/render_alert.py'], text=True )Technical Analysis
The subprocess target is specified as a path relative to the process's current working directory. It is not resolved relative to the trusted, installed location of
render_alert_text.py.Consequently, the invoked file can differ from the audited
scripts/render_alert.py. If execution starts in a directory containing an attacker-controlled file atskills/twitter-watch-reply/scripts/render_alert.py, Python will execute that file instead.No shell is used, so this is not shell-command injection. The weakness is executable-script path spoofing: the current working directory implicitly determines which Python source file receives execution privileges.
Attack Path
- An attacker gains permission to create files in a directory from which the user or Agent may invoke
render_alert_text.py. - The attacker creates:
skills/twitter-watch-reply/scripts/render_alert.py - The attacker places arbitrary Python code in that spoofed file.
- The user or Agent runs the legitimate
render_alert_text.pywhile the attacker-controlled directory is the current working directory. subprocess.check_output()startspython3with the relative path.- Python executes the spoofed script with the privileges and environment of the user or Agent.
This path requires the attacker to influence the working directory or its contents. It does not provide an unauthenticated remote attack by itself.
Impact Assessment
Successful exploitation permits arbitrary Python code execution with the invoking process's privileges. The malicious script could read accessible files and environment variabl ...[truncated 283 chars]
- An attacker gains permission to create files in a directory from which the user or Agent may invoke
- Remediation
View remediation
Remediation Suggestions
Prefer eliminating the subprocess and invoking trusted Python functions directly. Refactor alert construction into a shared function imported by both renderers.
If process isolation is required, resolve the target from the current script's trusted location and use the active Python interpreter:
python from pathlib import Path import subprocess import sys script_path = Path(__file__).resolve().parent / 'render_alert.py' raw = subprocess.check_output( [sys.executable, str(script_path)], text=True )Additional hardening should include:
- Verify that
script_pathis a regular file beneath the expected Skill directory. - Avoid depending on the caller's current working directory.
- Use
sys.executablerather than a PATH-resolvedpython3executable. - Run the Skill with a minimal environment and only the filesystem permissions needed for its data directory.
- Add a regression test that invokes
render_alert_text.pyfrom an unrelated directory containing a spoofed relative script and verifies that only the installed script can execute.
- Verify that
