T09 · Insecure Skill Coding Practices
- Location
search.sh:5- Finding
Unsafe JSON Construction from Command-Line Input
- Content
View full analysis
Vulnerability Details
File Location:
search.sh:5-11
Vulnerability Type: Improper escaping of user-controlled data in a JSON request body
Risk Level: Mediumbash QUERY="${1:-meeting}" curl -s -X POST \ -H "Authorization: Bearer $API_KEY" \ -H "Content-Type: application/json" \ -d "{\"query\": \"$QUERY\"}" \ "https://public.heypocketai.com/api/v1/public/search" | jq '.'Technical Analysis
The script interpolates the user-controlled
QUERYvalue directly into a JSON string without applying JSON escaping. A query containing quotation marks, backslashes, control characters, or JSON syntax can terminate the intended string and modify the structure of the outbound request body.For example, an argument resembling the following can introduce an additional JSON property:
text test", "additionalField": "attacker-controlledThis flaw is request-body injection rather than shell command injection. Shell syntax contained inside the expanded variable is not evaluated again by Bash, so the reviewed code does not provide direct operating-system command execution. Nevertheless, the request can be malformed or reshaped by anyone who controls the script argument.
Attack Path
- An attacker gains control over, or influences, the value passed as the first argument to
search.sh. - The script stores that value in
QUERY. - The value is inserted verbatim between JSON quotation marks.
- Embedded JSON delimiters terminate or alter the intended
queryfield. - The resulting malformed or attacker-shaped request is authenticated with the victim's Pocket AI API key and sent to the Pocket AI service.
- The remote API may reject the request or process attacker-supplied fields, depending on its schema and validation behavior.
Impact Assessment
The attacker can corrupt or manipulate the authenticated JSON request generated by this helper. The immediate scope is limited to ...[truncated 465 chars]
- An attacker gains control over, or influences, the value passed as the first argument to
- Remediation
View remediation
Remediation Suggestions
Construct the request with a JSON-aware serializer rather than string interpolation. For example:
bash #!/bin/bash set -euo pipefail API_KEY=$(cat ~/.config/pocket-ai/api_key) QUERY="${1:-meeting}" jq -n --arg query "$QUERY" '{query: $query}' | curl --fail --silent --show-error -X POST \ -H "Authorization: Bearer $API_KEY" \ -H "Content-Type: application/json" \ --data-binary @- \ "https://public.heypocketai.com/api/v1/public/search" | jq '.'This ensures that quotation marks, backslashes, newlines, and other special characters are encoded correctly. Additionally:
- Validate acceptable query length before submission.
- Use
--fail --silent --show-errorso HTTP failures are visible. - Enable
set -euo pipefailto prevent silent continuation after errors. - Add automated tests covering quotation marks, backslashes, Unicode, and newline characters.
