T09 · Insecure Skill Coding Practices
- Location
index.js:125- Finding
Shell Command Injection Through Unvalidated PR and Branch Values
- Content
View full analysis
${command}`); try { const output = execSync(command, { encoding: 'utf8', stdio: 'pipe' }); return { success: true, output }; } catch (error) { ``` ### Technical Analysis The `--pr` value is parsed directly from command-line input and embedded in shell command strings without validation or shell-safe argument separation. The target branch is similarly embedded into `git fetch` and `git merge` commands. Because `execSync()` receives a string, Node.js invokes shell parsing, and shell metacharacters contained in these values can introduce additional commands. The PR value is directly attacker- or caller-controlled. The branch value is obtained from GitHub PR metadata, which must also be considered untrusted. Quoting only selected file paths elsewhere does not protect these command constructions. ### Attack Path 1. An attacker convinces a privileged user or automation process ...[truncated 914 chars]- Remediation
View remediation
