T09 · Insecure Skill Coding Practices
- Location
SKILL.md:78- Finding
Command Injection Through User-Controlled File Paths
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 78-88
Vulnerability Type: OS command injection caused by unsafe shell interpolation
Risk Level: HighVulnerable Code
powershell Test-Path "E:\校对\报告.xlsx" Get-Item "E:\校对\报告.xlsx" | Select-Object Name, Length, LastWriteTimebash ls -la "/home/user/report.xlsx"Technical Analysis
The Skill instructs the Agent to extract a file path from an untrusted natural-language request and insert that path into a PowerShell or POSIX shell command executed through
exec.Merely surrounding the path with double quotation marks does not make this safe. PowerShell and POSIX shells perform expansions inside double-quoted strings. For example, PowerShell subexpressions and POSIX command substitutions can execute commands embedded in what appears to be a file path. A malicious value may also contain quotation marks and command separators that terminate the intended argument and introduce additional commands.
The preceding path normalization recommendations do not provide command escaping or establish that the path is safe for shell evaluation. Functions such as
normpathandabspathcanonicalize path syntax but are not defenses against shell metacharacters or command substitution.Attack Path
- An attacker submits a file-send request containing a crafted path with shell syntax, such as a command substitution or a closing quotation mark followed by a command separator.
- The Agent extracts the attacker-controlled string as the requested file path.
- Path normalization is applied but does not safely encode the value for the target shell.
- Following the Skill instructions, the Agent interpolates the resulting value into
Test-Path,Get-Item, orls. - The Agent invokes
exec. - The shell evaluates the injected syntax and executes the attacker's command with the privileges of the local Agent process.
Impact Assessment
...[truncated 638 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not use
execor a command shell to test file existence or retrieve metadata. Use a dedicated filesystem tool or a language API such asos.path.isfile,pathlib.Path.is_file, andPath.stat. - If an external process is unavoidable, invoke it without a shell and supply the path as a discrete argument. For example, use an argument array with
shell=Falserather than building a command string. - Reject null bytes, control characters, newlines, shell metacharacters, and other values that cannot be represented safely as a local path.
- Resolve symbolic links and canonicalize the path before access.
- Restrict eligible files to explicitly configured user-owned directories. Reject paths outside those roots after canonicalization.
- Require the target to be a regular file and reject directories, devices, named pipes, sockets, and other special files.
- Run the Agent under a dedicated least-privileged operating-system account with narrowly scoped filesystem access.
- Add tests covering quotation marks, semicolons, pipes, command substitutions, newlines, traversal sequences, symbolic links, and platform-specific shell syntax.
- Do not use
