T09 · Insecure Skill Coding Practices
- Location
SKILL.md:63- Finding
Unquoted User-Controlled URL in Shell Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 63 and 92
Vulnerability Type: Command injection through unsafe shell argument interpolation
Risk Level: MediumVulnerable Code
Line 63:
text Tier-1 (keyless, default): ask for current tags, target keywords, competitors, and page content; for `schema`, extract JSON-LD from server HTML with `WebFetch` or the bundled `python3 "${CLAUDE_PLUGIN_ROOT}/scripts/connectors/schema_lint.py" <url>` pre-flight.Line 92:
text Run the local pre-flight before the manual UI step: `python3 "${CLAUDE_PLUGIN_ROOT}/scripts/connectors/schema_lint.py" <url>` (extracts JSON-LD, checks required/recommended properties, flags these deprecations).Technical Analysis
The documented command places the user-supplied page URL into an unquoted shell argument. If an agent substitutes
<url>directly and executes the command through a shell, shell metacharacters in the URL—such as;,&&, redirection operators, or command substitution syntax—could be interpreted as additional commands rather than as part of one URL argument.The referenced
schema_lint.pyis outside the audited standalone package. Its implementation and integrity therefore could not be verified during this audit. This does not itself establish malicious behavior, but it increases reliance on an unaudited external component.Exploitability depends on the host executing the generated command through a shell without argument-safe process invocation or URL validation.
Attack Path
- An attacker submits a crafted page URL containing shell control syntax.
- The agent replaces the
<url>placeholder with the supplied value. - The agent executes the documented pre-flight command using a shell.
- The shell parses the injected metacharacters as command syntax.
- The injected command runs with the permissions of the agent host process.
Impact Assessment
Successful exploitation could permit arbitrary command execution u ...[truncated 429 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer the declared
WebFetchcapability instead of constructing a shell command for URL retrieval. - If the local script is necessary, invoke it through an argument-array process API, for example by passing
["python3", scriptPath, validatedUrl]without a shell. - Validate the input as an absolute
httporhttpsURL and reject control characters, shell metacharacters, embedded newlines, and unsupported schemes. - Do not interpolate raw user input into executable command strings.
- If a shell example must be retained, quote the URL argument and explicitly state that quoting is not a substitute for argument-safe execution and validation.
- Bundle
schema_lint.pywithin the reviewed package or pin it to a verified source and integrity hash so its behavior can be audited. - Add security tests using URLs containing spaces, semicolons, ampersands, substitutions, redirections, and newline characters to ensure they are passed only as inert data.
- Prefer the declared
