T09 · Insecure Skill Coding Practices
- Location
skill.yaml:66- Finding
Shell Command Injection Through Raw User Input Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a legitimate pet-sitting form generator, but its manifest tells the agent to place user-provided text into a shell command, which creates a review-worthy command execution risk.
Install only if you are comfortable with a skill that runs a local Python script through shell access. Avoid passing untrusted text into the form-generation prompt until the command template is changed to structured arguments, and consider omitting home-access fields unless needed. Completed intake PDFs may contain house-entry details, alarm codes, WiFi credentials, addresses, and emergency contacts, so store and share them securely.
skill.yaml:66Shell Command Injection Through Raw User Input Interpolation
requirements.txt:1Non-Reproducible Dependency Resolution Through Unbounded Version Ranges
Without declared permissions the skill's intent is opaque and cannot be validated.
The skill is designed to collect and generate documents containing highly sensitive personal and household security data, including alarm codes, entry methods, WiFi credentials, addresses, veterinarian contacts, and emergency information, yet it provides no privacy notice, minimization guidance, retention limits, or handling safeguards. In context, this is especially dangerous because pet-sitting intake forms routinely centralize everything needed for physical access to a home, making unauthorized disclosure materially harmful.
The authorization block states that the client gives permission for photos and videos to be shared before the later checkbox presents a Yes/No choice. That creates a consent contradiction and can lead to invalid or misleading authorization records, especially if users sign the overall agreement without noticing the later opt-out field. In the pet-sitting context, this is more concerning because client forms are intended to document permissions and may be relied on operationally or legally.
This code generates and saves a PDF containing sensitive personal and home-entry details collected elsewhere in the form, including alarm codes, Wi‑Fi passwords, addresses, and emergency contacts. Although it prints that the form was saved, it does not disclose that the output file may contain highly sensitive information or advise the user to handle/store it securely.
The manifest defines generic trigger phrases such as "client intake form", "new client form", and "boarding form" without narrowing context or providing exclusion conditions. In a natural-language entry point, these phrases could match ordinary conversation outside the intended pet-sitting skill scope.
The dependency is specified with a lower bound only, which allows future installs to resolve to different versions over time. This weakens supply-chain control and makes it harder to ensure the project consistently uses a version of reportlab that is known to be free of relevant security issues.
# Pet Sitter Intake Form Generator - Dependencies
# PDF generation (required)
reportlab>=4.0.0
# YAML config support (optional but recommended)
pyyaml>=6.0
ReportLab has multiple historical advisories, including issues that can become serious when generating PDFs from untrusted content. Because the manifest does not pin a version, there is no assurance that deployments will avoid vulnerable releases, and this skill’s purpose of producing client-facing PDFs makes the library directly relevant to the attack surface.
The dependency is not pinned to an exact version, so builds are non-reproducible and may unexpectedly pull in a vulnerable or incompatible PyYAML release. For a package with a history of unsafe deserialization issues, leaving version selection open increases supply-chain risk.
reportlab>=4.0.0
# YAML config support (optional but recommended)
pyyaml>=6.0
PyYAML has a well-known history of unsafe parsing and deserialization flaws when used on untrusted YAML. Since the version is not pinned, the project cannot demonstrate that installed environments avoid affected releases, and optional configuration support may still become dangerous if YAML input is later accepted from users or shared templates.
No suspicious patterns detected.