T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Command Injection Through Unvalidated Windows Command Parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:24-45
Vulnerability Type: OS command injection caused by unvalidated command parameters
Risk Level: HighVulnerable Code
bash # Kill by name /mnt/c/Windows/System32/taskkill.exe /F /IM chrome.exe # Kill by PID /mnt/c/Windows/System32/taskkill.exe /F /PID 1234Launch Applications
bash # Open a URL in default browser /mnt/c/Windows/System32/cmd.exe /c "start https://google.com" # Open an app by name /mnt/c/Windows/System32/cmd.exe /c "start chrome" /mnt/c/Windows/System32/cmd.exe /c "start spotify" /mnt/c/Windows/System32/cmd.exe /c "start notepad" # Open a file with its default app /mnt/c/Windows/System32/cmd.exe /c "start C:\\Users\\User\\file.pdf" # Launch full path /mnt/c/Windows/System32/cmd.exe /c "start \"\" \"C:\\Program Files\\App\\app.exe\""Technical Analysis
The Skill instructs the agent to adapt these command templates to user-supplied process names, process identifiers, URLs, application names, and file paths. It does not require validation, canonicalization, allowlisting, or context-appropriate escaping before placing those values into Bash commands or a
cmd.exe /ccommand string.The process-management examples leave the process name and PID arguments unquoted. If an agent substitutes request text directly into these templates, Bash metacharacters can terminate or extend the intended command.
The application-launch examples introduce a second command interpreter through
cmd.exe /c. Quotes interpreted by Bash do not prevent the resulting string from subsequently being parsed bycmd.exe. A value containing command separators or crafted quote characters can therefore alter the command interpreted by Windows rather than remaining a URL, application name, or path.Although the examples contain static benign values, their documented purpose requires adapting those values to user requests. The a ...[truncated 1513 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not place raw request text into Bash or
cmd.exe /ccommand strings. - Validate PIDs using a strict positive-integer pattern and verify the selected process name and PID before termination.
- Resolve application requests through a fixed allowlist that maps supported names to trusted executable paths. Reject arbitrary executable names unless the user explicitly approves a verified path.
- Canonicalize file paths, require them to remain within user-approved directories, and reject control characters, unexpected quotes, and shell metacharacters.
- Validate URLs with a structured parser and allow only approved schemes such as
httpsand, where necessary,http. - Prefer structured process-launch APIs that pass an executable and argument array separately instead of invoking
cmd.exe /c. - If a command interpreter is unavoidable, apply escaping specifically designed for both the outer Bash context and the inner Windows command context.
- Display the resolved executable, process, URL, or canonical file path and obtain explicit confirmation before forced process termination or other destructive operations.
- Add explicit instructions that agents must reject parameters containing command separators, redirection operators, newline characters, or unmatched quotes rather than attempting to sanitize ambiguous input.
- Do not place raw request text into Bash or
