T09 · Insecure Skill Coding Practices
- Location
SKILL.md:164- Finding
Command Injection in Documented Portfolio Management Operations
- Content
View full analysis
/dev/null; then echo "DUPLICATE:{code}" else echo "{code},{name},{shares},{cost}" >> "$PFILE" && echo "ADDED:{code},{name},{shares},{cost}" fi ``` ```bash OLD=$(grep "^{code}," "$PFILE") if [ -z "$OLD" ]; then echo "NOT_FOUND:{code}" else NEW="{code},{name},{shares},{cost}" tmp=$(mktemp) awk -F',' -v c="{code}" -v n="$NEW" \ 'BEGIN{OFS=","} $1==c{print n;next}{print}' "$PFILE" > "$tmp" && mv "$tmp" "$PFILE" echo "BEFORE:$OLD" echo "AFTER:$NEW" fi ``` ```bash DEL=$(grep "^{code}," "$PFILE") if [ -z "$DEL" ]; then echo "NOT_FOUND:{code}" else tmp=$(mktemp) grep -v "^{code}," "$PFILE" > "$tmp" && mv "$tmp" "$PFILE" echo "DELETED:$DEL" fi ``` ### Technical Analysis The Skill instructs the agent to construct executable Bash source by replacing placeholders such as `{code}`, `{name}`, `{shares}`, and `{cost}` with values obtained from user input or remote market-data responses. There is no requirement to validate or safely encode these values before inserting them into the command text. Values placed inside double-quoted Bash strings are still subject to command substitution, parameter expansion, and backtick expansion when the resulting command is interpreted by Bash. Quote-breaking input can also alter the command structure. For example, if a supplied portfolio field is substituted as `$(id)`, the generated command can contain: ```bash NEW="AAPL,Apple,$(id),220.00" ``` Bash executes `id` while assigning `NEW`. More complex substitutions could read or modify files or execute another local program. Similar risks exist in the `grep` expressions, where unescaped values are interpreted as regular expressions. Although these operations appear in documenta ...[truncated 1465 chars]- Remediation
View remediation
