T09 · Insecure Skill Coding Practices
- Location
scripts/send_to_kindle.py:12- Finding
AppleScript Injection Through Unescaped User-Controlled Arguments
- Content
View full analysis
bool: """Send file to Kindle using Mail.app AppleScript.""" applescript = f''' tell application "Mail" set newMessage to make new outgoing message with properties {{subject:"{subject}", visible:false}} tell newMessage make new to recipient at end of to recipients with properties {{address:"{kindle_email}"}} set content to "Sent from blog-to-kindle skill." make new attachment with properties {{file name:"{file_path}"}} at after the last paragraph end tell send newMessage end tell ''' result = subprocess.run( ["osascript", "-e", applescript], capture_output=True, text=True ) ``` ## Technical Analysis The `subject`, `kindle_email`, and `file_path` values are inserted directly into AppleScript source code using an f-string. None of these values are escaped before being placed inside AppleScript string literals. Although `subprocess.run` does not invoke a shell here, it executes the dynamically generated source through `osascript`. An attacker who controls one of the interpolated values can supply quotation marks and additional AppleScript statements that terminate the intended string and modify the script's behavior. The subject and recipient are directly controllable through command-line arguments. The file path can also contain attacker-selected characters if the attacker can choose or create the attachment filename. Injected AppleScript can invoke other applications or use `do shell script` to execute local commands. ### Attack Path 1. An attacker causes the script to be invoked with a malicious `--subject`, `--kindle-email`, ...[truncated 1207 chars]- Remediation
View remediation
