T09 · Insecure Skill Coding Practices
- Location
scripts/aitubiao-cli.sh:64- Finding
Arbitrary Command Execution Through Executable Credential File
- Content
View full analysis
&2 echo "Please configure credentials first. See SKILL.md for setup instructions." >&2 exit 1 fi source "$CREDENTIALS_FILE" ``` ```bash cmd_auth() { local api_key="${1:-}" if [[ -z "$api_key" ]]; then echo "Error: API Key required. Usage: aitubiao-cli.sh auth " >&2 echo "Get one at: https://app.aitubiao.com/setting/api-keys?utm_source=skill_skill-clawhub&channel=skill-clawhub" >&2 exit 4 fi if [[ ! "$api_key" =~ ^sk_v1_ ]]; then echo "Error: Invalid API Key format (must start with sk_v1_)" >&2 echo "Get a valid key at: https://app.aitubiao.com/setting/api-keys?utm_source=skill_skill-clawhub&channel=skill-clawhub" >&2 exit 4 fi mkdir -p "$(dirname "$CREDENTIALS_FILE")" cat > "$CREDENTIALS_FILE" << EOF API_KEY=$api_key BASE_URL=https://api.aitubiao.com CHANNEL=skill-clawhub EOF chmod 600 "$CREDENTIALS_FILE" ``` ### Technical Analysis The credential loader executes `~/.aitubiao/credentials` as shell code by using `source`. The `auth` command writes the supplied API key directly into that executable file without shell-safe serialization. Validation only requires the value to begin with `sk_v1_`. It does not validate the complete value or reject shell metacharacters, command substitutions, whitespace, or newline characters. Consequently, attacker-controlled shell syntax can be persisted after the accepted prefix. Although the file is assigned mode `0600`, those permissions only restrict other users from reading or modifying it. They do not prevent malicious content supplied through the `auth` argument from being execu ...[truncated 1289 chars]- Remediation
View remediation
