T09 · Insecure Skill Coding Practices
- Location
SKILL.md:16- Finding
Potential Shell Command Injection Through Unsanitized Skill Arguments
- Content
View full analysis
" --before="" --author="$1" --pretty=format:"%h %s" --no-merges ``` Convert the date `$0` (format: `YYYY.MM.DD`) to proper git date range: - `--after` = the date at 00:00:00 - `--before` = the next day at 00:00:00 2. Also run `git log` with `--stat` to understand the scope of changes: ``` git log --after="" --before="" --author="$1" --stat --no-merges ``` ``` ### Technical Analysis The Skill permits use of the Bash tool and directs the agent to construct shell commands using a user-provided date and author. It does not require validation of either input or prescribe a safe argument-passing mechanism. If an implementation performs textual substitution when replacing `$1`, ``, or ``, an attacker may provide quotation marks, command substitutions, control characters, or shell metacharacters that terminate the intended argument and introduce additional shell syntax. Surrounding a placeholder with double quotes is insufficient when untrusted content is inserted into the command string before the shell parses it. Exploitation depends on how the invoking agent performs interpolation. Passing values directly as already-separated process arguments would prevent this issue, while constructing and executing a shell command string may expose it. ### Attack Path 1. An attacker invokes the Skill with a crafted author name or date containing shell syntax. 2. The agent converts the supplied values into the documented `git log` command through textual interpolation. 3. The malicious input breaks out of the intended quoted argument or introduces command substitution. 4. Bash parses the injected syntax as an additional command. 5. The injected command exec ...[truncated 801 chars]- Remediation
View remediation
