T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Arbitrary Shell Command Execution Through Sourcing Untrusted Decrypted Content
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a plausible secrets-encryption helper, but it recommends loading decrypted secrets by executing them as shell code and uses an over-specific root key path.
Install only if you are comfortable auditing and changing the workflow first. Do not source decrypted files from repositories or shared workspaces; decrypt only trusted files, validate simple key-value assignments before loading them, avoid running this as root, and reconcile the `/root/.age/key.txt` versus `$HOME/.age/key.txt` inconsistency.
SKILL.md:24Arbitrary Shell Command Execution Through Sourcing Untrusted Decrypted Content
The skill is presented primarily as an encryption utility, but its documented behavior also includes decrypting secrets, reading a private key from /root/.age/key.txt, and emitting plaintext secrets to stdout for shell sourcing. That mismatch is dangerous because users may approve it as a storage-protection tool without realizing it also performs secret recovery and disclosure operations.
Referenced artifact was not completely inspected
bash scripts/secure/setup.sh
Referenced artifact was not completely inspected
bash scripts/secure/setup.sh
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash scripts/secure/setup.sh
# 2. Encrypt a secret
echo 'export API_KEY=*** | bash scripts/secure/encrypt.sh scripts/secure/secrets.env.age
# 3. Decrypt on the fly
source <(bash scripts/secure/decrypt.sh scripts/secure/secrets.env.age)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
bash scripts/secure/setup.sh
# 2. Encrypt a secret
echo 'export API_KEY=*** | bash scripts/secure/encrypt.sh scripts/secure/secrets.env.age
# 3. Decrypt on the fly
source <(bash scripts/secure/decrypt.sh scripts/secure/secrets.env.age)
The documented decryption flow outputs plaintext secrets and immediately sources them into the shell, which constitutes active credential exposure in memory and process output paths. In agent or shared environments, this can disclose secrets to logs, command tracing, shell introspection, or malicious content embedded in the encrypted file.
echo 'export API_KEY=*** | bash scripts/secure/encrypt.sh scripts/secure/secrets.env.age
source <(bash scripts/secure/decrypt.sh scripts/secure/secrets.env.age)
## Files
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
echo ""
echo "[*] AHORA: cifra tus secrets manualmente:"
echo " echo 'export API_KEY=xxx' | $SCRIPTS_DIR/encrypt.sh $SCRIPTS_DIR/secrets.env.age"
echo " rm -f /ruta/al/archivo.original"
echo ""
echo "[*] Para descifrar:"
echo " source <($SCRIPTS_DIR/decrypt.sh $SCRIPTS_DIR/secrets.env.age)"
The script instructs users to load decrypted content directly into the current shell with source <(decrypt.sh ...). If the encrypted file is modified by an attacker or contains unexpected shell code, this executes arbitrary commands in the user's session rather than merely reading environment variables, turning secret handling into code execution.
echo " rm -f /ruta/al/archivo.original"
echo ""
echo "[*] Para descifrar:"
echo " source <($SCRIPTS_DIR/decrypt.sh $SCRIPTS_DIR/secrets.env.age)"
The skill invokes shell commands and external executables (bash, age) but does not declare any tool scope or permissions boundary. In an agent environment, this creates hidden execution capability and prevents users or orchestrators from understanding or constraining what the skill can run.
The instructions recommend source <(bash scripts/secure/decrypt.sh ...), which executes decrypted content directly in the current shell without warning. If the encrypted file contains unexpected shell code instead of simple environment assignments, decryption becomes code execution in the user's session and may expose secrets via shell history, process inspection, or follow-on commands.
The script states that the private key must be present at /root/.age/key.txt and then uses it directly to decrypt data. There is no confirmation prompt, user-facing warning beyond the usage note, or explanatory disclosure about handling sensitive credentials in this code file.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 1. Generar par de llaves
AGE_DIR="$HOME/.age"
mkdir -p "$AGE_DIR"
chmod 700 "$AGE_DIR"
if [ ! -f "$AGE_DIR/key.txt" ]; then
age-keygen -o "$AGE_DIR/key.txt"
The file's descriptive comments and usage guidance are written only in Spanish, which imposes a specific language without any opt-in or indication that the skill is region-specific. Under the stated policy, language constraints should either be optional for the user or explicitly justified.
This code performs a file write by redirecting encryption output into the path provided by the caller. While writing the output file is central to the script's purpose, the script does not include any explicit disclosure that an existing file may be overwritten or replaced, which is a safety-relevant side effect for code files.
No suspicious patterns detected.