T09 · Insecure Skill Coding Practices
- Location
skill.py:9- Finding
Unsandboxed Execution of User-Supplied Python, C, and Assembly Code
- Content
View full analysis
str: def run(c): with tempfile.NamedTemporaryFile(suffix=".py", delete=False) as f: f.write(c.encode()) try: return safe_run(["python3", f.name]) finally: os.unlink(f.name) return await auto_run_and_fix(code, "python", run) @server.tool() async def run_c(code: str) -> str: def run(c): with tempfile.NamedTemporaryFile(suffix=".c", delete=False) as f: f.write(c.encode()) ex = f.name + ".out" try: _, compile_err = safe_run(["gcc", f.name, "-o", ex]) if compile_err: return "", compile_err return safe_run([ex]) finally: if os.path.exists(ex): os.unlink(ex) os.unlink(f.name) return await auto_run_and_fix(code, "c", run) @server.tool() async def run_assembly(code: str) -> str: def run(c): with tempfile.NamedTemporaryFile(suffix=".asm", delete=False) as f: f.write(c.encode()) o = f.name + ".o" ex = f.name + ".out" try: _, asm_err = safe_run(["nasm", "-f", "elf64", f.name, "-o", o]) if asm_err: return "", asm_err _, link_err = safe_run(["ld", o, "-o", ex]) if link_err: ...[truncated 2693 chars]- Remediation
View remediation
