T09 · Insecure Skill Coding Practices
- Location
scripts/collect_detail.py:132- Finding
Shell Command Injection Through Untrusted URLs, Keywords, and Command Templates
- Content
View full analysis
dict: env = os.environ.copy() env["DISPLAY"] = env.get("DISPLAY", ":99") work_dir = Path(tempfile.gettempdir()) / "dailynew-opencli-web" / hashlib.md5(url.encode("utf-8")).hexdigest() if work_dir.exists(): shutil.rmtree(work_dir, ignore_errors=True) work_dir.mkdir(parents=True, exist_ok=True) cmd = f'opencli web read --url "{url}" --format md --output "{work_dir}"' try: result = subprocess.run( cmd, shell=True, capture_output=True, text=True, timeout=timeout, env=env ) ``` ```python # scripts/collect_sources_with_opencli.py def run_opencli(cmd: str, timeout: int = 30, platform: str = "") -> dict: full_cmd = f"opencli {cmd}" env = os.environ.copy() env["DISPLAY"] = env.get("DISPLAY", ":99") try: result = subprocess.run( full_cmd, shell=True, capture_output=True, text=True, timeout=timeout, env=env ) ``` ```python # scripts/collect_sources_with_opencli.py for cmd_template in commands: if "{keyword}" in cmd_template: for kw in keywords: cmd = f'{opencli_prefix} {cmd_template.replace("{keyword}", kw)} -f json' print(f" [{name}] {cmd}", file=sys.stderr) res = run_opencli(cmd, platform=opencli_prefix) else: cmd = f"{opencli_prefix} {cmd_template} -f json" print(f" [{name}] {cmd}", file=sys.stderr) res = run_opencli(cmd, platform=opencli_prefix) ``` ### Technical Analysis The scripts concatenate untrusted values into shell command strings and execute those strings with `shell=True`. In `collect_detail.py`, the `url` value is parsed fr ...[truncated 2323 chars]- Remediation
View remediation
