T09 · Insecure Skill Coding Practices
- Location
SKILL.md:60- Finding
Shell Command Injection Through Unescaped Tool Arguments
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 60-70
Vulnerability Type: Shell command injection through unsafe command templates
Risk Level: HighThe documented tool calls interpolate user-controlled email addresses, usernames, and search queries directly into shell command strings:
markdown ### `scan_email` Checks 120+ sites to see if an email is registered using forgotten password flows. - **Inputs:** `email` (string) - **Call:** `python3 monitor.py --tool scan_email --target {{email}}` ### `scan_username` Hunts for a specific username across 400+ social networks and platforms. - **Inputs:** `username` (string) - **Call:** `python3 monitor.py --tool scan_username --target {{username}}` ### `search_leaks` Uses advanced Google Dorks to find identifiers on leak sites, forums, and pastebins. - **Inputs:** `query` (string) - **Call:** `python3 monitor.py --tool search_leaks --query "{{query}}"`Technical Analysis
The
emailandusernameplaceholders are completely unquoted. If the skill runtime expands these templates and executes the resulting text through a shell, shell metacharacters in an attacker-controlled value are interpreted as command syntax rather than as part of a single argument.Although the
queryplaceholder is surrounded by double quotes, an attacker can include a double quote in the supplied value to terminate the quoted argument and then introduce shell operators. Quoting the template without escaping the interpolated data therefore does not establish a security boundary.The Python subprocess calls in
monitor.pyuse argument arrays and do not independently invoke a shell. The injection occurs one layer earlier if the documented skill call is rendered into a shell command.Attack Path
- An attacker supplies a crafted value through a request handled by the skill. For example, an email or username could contain
x; touch /tmp/skill-injection.
...[truncated 1044 chars]
- An attacker supplies a crafted value through a request handled by the skill. For example, an email or username could contain
- Remediation
View remediation
Remediation Suggestions
- Do not represent tool invocation as a shell command assembled through textual interpolation.
- Invoke the program through an argument array, preserving each user value as one argument. For example:
python subprocess.run( ["python3", "monitor.py", "--tool", "scan_email", "--target", email], check=True, shell=False, ) - Apply the same approach to username and query operations.
- Explicitly prohibit shell execution mechanisms such as
shell=True,sh -c, or equivalent wrappers for these calls. - Validate inputs before invocation. Enforce an email format and reasonable length for email input, a conservative platform-compatible character set for usernames, and maximum lengths for all fields.
- If command-string generation is unavoidable, use a platform-appropriate argument-escaping function for every interpolated value. Escaping is a fallback and should not replace argument-array execution.
- Run the skill in a restricted account or container with minimal filesystem access, no unnecessary credentials, and constrained outbound networking to reduce the impact of any future command-execution flaw.
