T09 · Insecure Skill Coding Practices
- Location
scripts/image_to_relief.sh:80- Finding
Arbitrary Python Code Execution Through an Injected Input Filename
- Content
View full analysis
10 and (r,g,b) != bg: mask.putpixel((x,y), 0) mask.save("$TMPDIR/preview.pbm") PY ``` ### Technical Analysis The optional SVG preview implementation embeds the attacker-controllable `$IN` value directly into Python source code inside an unquoted heredoc. Shell quoting used when initially assigning `IN="$1"` does not protect the value when it is subsequently inserted into generated Python code. Because the heredoc delimiter is unquoted, the shell expands `$IN` before passing the script to Python. A filename containing quotation marks, newlines, comment characters, or Python expressions can terminate the intended string literal and introduce arbitrary Python statements. For example, a malicious argument can be constructed so that the generated source is conceptually transformed into: ```python img = Image.open("legitimate-file.png") __import__("os").system("attacker-command") #").convert('RGBA') ``` The injected code is executed by the virtual-environment Python interpreter with the same operating-system privileges as the user or Agent invoking the Skill. The vulnerable path is reached only when the optional `--preview-svg` feature is requested. ### Attack Path 1. An attacker creates or supplies an image path containing Python syntax, including a quote and newline characters. 2. The attacker causes the Skill or an orchestrating Agent to invoke `image_to_relief.sh` with that path as its first argument. 3. The invocation includes `--preview-svg`, causing execution ...[truncated 1317 chars]- Remediation
View remediation
10 and (r, g, b) != bg: mask.putpixel((x, y), 0) mask.save(output_path) PY ``` Additional hardening measures: 1. Retain shell quoting around all path arguments passed to external commands. 2. Validate that the input path refers to an expected regular image file where the deployment model permits such restrictions. 3. Avoid dynamically constructing executable source from user-controlled values. 4. Add regression tests using filenames containing quotes, newlines, spaces, shell metacharacters, and Python syntax. 5. Run image processing in a restricted execution environment when processing files or paths supplied by untrusted parties. ]]>
