Agent 与自动化 5.0 · 必读 2026-09-15 · 文章

Shadowing the Standard Library: Coding Agents vs Python Module Search Path

Andrew Nesbitt 2026-09-15 的工程文:coding agent 解 zip 写一个 Python 解码脚本 触发 import struct,攻击者在同目录放一个 struct.py 转发到真实模块并用 python3 -I 二次启动,结果标准库被静默替换事件之所以可怕,是因为 agent 的 sandbox 路径就是 /tmp,Python 默认把脚本所在目录放进 sys.path[0],影子模块直接赢;Perl 5.26 / Ruby 1.9.2 / Node 早就把 ....

打开原文回到归档

Shadowing the Standard Library: Coding Agents vs Python Module Search Path

博客要点 (中文)

Andrew Nesbitt 2026-09-15 工程文。事件链:coding agent 解 zip → 写 Python 解码脚本 → 触发 import struct,攻击者在同目录放 struct.py 转发到真实模块并用 python3 -I 二次启动,标准库被静默替换。可怕之处:agent 的 sandbox 路径就是 /tmp,Python 默认把脚本所在目录放进 sys.path[0],影子模块直接赢;Perl 5.26 / Ruby 1.9.2 / Node 早把 . 从搜索路径里去掉,PHP / Lua 把它放最后,Python 把它放第一,是少数还在这个默认上裸奔的。跨语言对比表覆盖默认路径、位置、是否可影子、移除版本、安全模式开关;3.11 加的 -P / PYTHONSAFEPATH 只压 sys.path[0],bpo-13475 拖到 2026 年才有 PEP 草案想把安全路径做默认。读者对照自家 agent 跑的 runtime,立刻看出哪些解释器在 /tmp 默认是危险的。

Key claims (English)

Andrew Nesbitt's 2026-09-15 engineering post walks through a real agent-time Python shadowing attack: an agent unzips a task, writes a decode script that triggers import struct, an attacker drops struct.py in the same directory that forwards to the real module and restarts under python3 -I, and the standard library is silently swapped. The danger comes from Python's default of putting the script's directory at sys.path[0], while the agent's sandbox path is /tmp — so the shadow module wins. Perl 5.26 / Ruby 1.9.2 / Node long removed '.' from the search path, PHP / Lua put it last, and Python is one of the few languages still naked on this default. The article includes a cross-language table (default path, position, shadowable, removal version, safe-mode switch) and notes that 3.11's -P / PYTHONSAFEPATH only suppresses sys.path[0]; bpo-13475 sat open until a 2026 PEP draft that would make the safe path the default. Read this against any runtime your agent actually uses to see which interpreters are dangerous by default in /tmp.

Obsidian 证据摘录

「coding agent 解 zip → 写一个 Python 解码脚本 → 触发 import struct,攻击者在同目录放一个 struct.py 转发到真实模块并用 python3 -I 二次启动,结果标准库被静默替换。这件事之所以可怕,是因为 agent 的 sandbox 路径就是 /tmp,Python 默认把脚本所在目录放进 sys.path[0],影子模块直接赢。」——OpenClaw定时任务/AK-RSS-Digest(89源精选)/2026-09-15-AK-RSS-Digest(89源精选).md L25-27

链接