Skip to content

[DRAFT] feat: add top-level sandbox SDK with Substrate integration - #75

Open
Sunny (sunnylovestiramisu) wants to merge 1 commit into
agent-substrate:mainfrom
sunnylovestiramisu:sandbox
Open

Sunny (sunnylovestiramisu) wants to merge 1 commit into
agent-substrate:mainfrom
sunnylovestiramisu:sandbox

Conversation

@sunnylovestiramisu

Copy link
Copy Markdown
Collaborator

For discussion

@wiz-alphabet

wiz-alphabet Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities -
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations -
SAST Finding SAST Findings 1 High
Software Management Finding Software Management Findings -
Total 1 High

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try the Wiz Code extension for VS Code, JetBrains, or Visual Studio.

Comment on lines +72 to +73
proc = subprocess.Popen(cmd, cwd=cwd, env=env, stdout=subprocess.PIPE,
stderr=subprocess.PIPE, start_new_session=True)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

High SAST Finding

Command Injection in Subprocess Calls (CWE-78)
Analyzed by AI as Inconclusive

More Details

Detected user input entering a subprocess call unsafely. This could result in a command injection vulnerability. An attacker could use this vulnerability to execute arbitrary commands on the host, which allows them to download malware, scan sensitive data, or run any command they wish on the server. Do not let users choose the command to run. In general, prefer to use Python API versions of system commands. If you must use subprocess, use a dictionary to allowlist a set of commands.

Attribute Value
Impact High
Likelihood Medium

AI Analysis

The snippet shows subprocess.Popen(cmd, ...) being called, but the source of cmd is not visible in the provided code. Without seeing how cmd is constructed or where it originates from, it's unclear whether user input directly flows into it unsafely. The snippet alone is insufficient to determine if this is exploitable—additional context about cmd's origin is needed to assess the actual injection risk.

Remediation

Command injection vulnerabilities occur when user-supplied input is passed unsanitized to a system command execution function like subprocess.run(). This allows an attacker to execute arbitrary commands on the host system, leading to data theft, malware installation, or full system compromise.

To fix this issue, user input should never be directly passed to command execution functions. Instead, use Python APIs for system operations whenever possible. If you must use subprocess, validate and sanitize all input, and use a whitelist to strictly control allowed commands.

Code examples

# VULNERABLE CODE - User input is passed directly to subprocess.run()
import subprocess

def run_command(user_input):
    result = subprocess.run(user_input, shell=True)
    return result.stdout
# SECURE CODE - Use Python APIs instead of subprocess when possible
import os

def list_files(directory):
    return os.listdir(directory)

If you must use `subprocess`, sanitize input and use a whitelist:
# SECURE CODE - Whitelist allowed commands and sanitize input
import subprocess

ALLOWED_COMMANDS = ["ls", "grep", "find"]

def run_command(user_input):
    if user_input in ALLOWED_COMMANDS:
        sanitized_input = [user_input] # Run command directly, no shell
        result = subprocess.run(sanitized_input, stdout=subprocess.PIPE)
        return result.stdout.decode()
    else:
        return "Command not allowed"

Additional recommendations

  • Follow the principle of least privilege and run commands with minimal permissions
  • Implement secure coding practices like input validation per OWASP guidelines
  • Consider using parameterized APIs or ORMs instead of constructing OS commands
  • Perform thorough testing, code review, and penetration testing to identify injection flaws

Rule ID: WS-I013-PYTHON-00058


To ignore this finding as an exception, reply to this conversation with #wiz_ignore reason

If you'd like to ignore this finding in all future scans, add an exception in the .wiz file (learn more) or create an Ignore Rule (learn more).

@rakyll

Copy link
Copy Markdown
Collaborator

We already have a sandbox SDK in the clients directory. What's missing in them?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants