T09 · Insecure Skill Coding Practices
- Location
SKILL.md:56- Finding
Shell Command Injection Through Unescaped Dynamic Arguments
- Content
View full analysis
" ``` ```bash notesmd-cli daily --content "" --vault "{vault-name}" ``` ```bash # Create a new note (leaves existing notes unchanged if no flag) notesmd-cli create "{note-path}" --content "..." --vault "{vault-name}" # Append to an existing note notesmd-cli create "{note-path}" --content "..." --append --vault "{vault-name}" # Overwrite an existing note (only with explicit user consent) notesmd-cli create "{note-path}" --content "..." --overwrite --vault "{vault-name}" ``` The vault-registration workflow uses the same unsafe command-template pattern: ```bash notesmd-cli add-vault /path/to/vault --set-default ``` ### Technical Analysis The Skill instructs an agent to interpolate dynamic note content, note paths, vault names, and vault paths directly into shell command strings. Surrounding values with double quotes does not make arbitrary input safe for shell interpretation. If a substituted value contains a double quote, it can terminate the quoted argument. Shell metacharacters can then introduce additional commands. Command substitutions such as `$(command)` and backtick expressions may also be evaluated inside double-quoted shell arguments. For example, if note content is inserted without shell-safe argument handling, a value conceptually shaped like the following can escape the intended argument: ```text "; attacker-command; # ``` This risk applies especially to content received from users, external documents, or the output of another skill. The Skill does not require use of an argument-array API, define an escaping procedure, reject shell metacharacters, or provide a standard-input/file-based mechanism for arbitrary content. ### Attack Path 1. ...[truncated 1401 chars]- Remediation
View remediation
