T09 · Insecure Skill Coding Practices
- Location
scripts/t2i.sh:20- Finding
Unescaped User Input Allows JSON Request-Body Injection
- Content
View full analysis
- Remediation
View remediation
[negative_prompt] [size]" >&2 exit 1 fi PROMPT="$1" NEGATIVE_PROMPT="${2:-}" SIZE="${3:-1280*1280}" if [ -z "${DASHSCOPE_API_KEY:-}" ]; then echo "Error: DASHSCOPE_API_KEY environment variable is not set" >&2 exit 1 fi case "$SIZE" in 1280x1280|720x1280|1280x720|1280\*1280|720\*1280|1280\*720) ;; *) echo "Error: unsupported image size" >&2 exit 1 ;; esac payload=$(jq -n \ --arg prompt "$PROMPT" \ --arg negative_prompt "$NEGATIVE_PROMPT" \ --arg size "$SIZE" \ '{ model: "wan2.6-t2i", input: { messages: [{ role: "user", content: [{text: $prompt}] }] }, parameters: { prompt_extend: true, watermark: false, n: 1, negative_prompt: $negative_prompt, size: $size } }') curl --fail-with-body --location \ 'https://dashscope.aliyuncs.com/api/v1/services/aigc/multimodal-generation/generation' \ --header 'Content-Type: application/json' \ --header "Authorization: Bearer $DASHSCOPE_API_KEY" \ --data-binary "$payload" ``` Additional hardening measures: 1. Enforce an exact allowlist for supported image dimensions using the representation required by the API. 2. Set reasonable maximum lengths for prompts and negative prompts. 3. Use `set -euo pipefail` and `curl --fail-with-body` so local callers can detect failures. 4. Keep the API key exclusively in the environment or a managed secret store and ensure it is never logged. 5. Test inputs containing quotes, backslashes, newlines, and JSON fragments to verify that they remain ordinary string data in the serialized request. ]]>
