T09 · Insecure Skill Coding Practices
- Location
SKILL.md:25- Finding
Shell Command Injection Through an Unvalidated Base Branch Argument
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15,25
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable Code Snippet:
markdown - `--base <branch>`: Base branch for diff comparison (default: `main`)bash git diff --name-only $(git merge-base HEAD <base>)..<HEAD> | grep -E '(SKILL\.md|skills/[^/]+/)'Technical Analysis
The caller-controlled
--basevalue is inserted unquoted into a shell command and nested command substitution. The workflow does not require validation that the value is a legitimate Git reference or prohibit shell metacharacters and option-like input.If the agent substitutes a malicious argument verbatim and executes the documented command through a shell, command separators, substitutions, or other shell syntax in the value can alter the intended operation. The nested
$(...)expression makes this especially dangerous because injected syntax may be evaluated as part of command construction.Attack Path
- An attacker supplies a crafted value through the documented
--baseargument. - The agent substitutes that value for
<base>in the command at line 25. - The resulting command is passed to a shell without quoting or strict validation.
- The shell interprets attacker-provided metacharacters rather than treating the entire value as a Git branch name.
- Injected commands execute with the same operating-system privileges and filesystem access as the agent process.
Impact Assessment
Successful exploitation can provide arbitrary command execution within the agent's security context. The attacker could read or modify accessible repository files, overwrite configuration, extract locally available data, manipulate audit results, or invoke other installed tools. The scope is bounded by the operating-system privileges, sandbox restrictions, credentials, and network access available to the agent.
- An attacker supplies a crafted value through the documented
- Remediation
View remediation
Remediation Suggestions
- Validate the supplied base branch before use, such as with
git check-ref-format --branch. - Reject values containing whitespace, shell metacharacters, control characters, or a leading hyphen.
- Do not construct commands by interpolating input into a shell string. Invoke Git through an argument-array API so the branch value remains a single literal argument.
- Resolve and verify the revision separately, then pass the validated revision to
git merge-baseandgit diff. - Use appropriate
--option terminators where supported to prevent option injection. - Abort safely with a clear error if validation or revision resolution fails.
- Validate the supplied base branch before use, such as with
