T09 · Insecure Skill Coding Practices
- Location
references/current.md:9- Finding
Remote API Response Can Be Interpreted as a Local Shell Command
- Content
View full analysis
Vulnerability Details
File Location:
references/current.md:9-10; related schema inreferences/beatapi.openapi.yaml:2173-2182
Vulnerability Type: Remote-response command injection
Risk Level: HighVulnerable instructions:
markdown **Every response has a `next` field: the exact call to make next, written for your transport.** Copy it and replace the `<placeholders>`. Copy references exactly as returned; never invent one.Related API schema:
yaml CapabilityNext: type: object required: [action] description: 'The call to make next, in the caller''s dialect: an MCP tool call `{tool, arguments}` when the request sent `X-Beat-Client: mcp`, otherwise a complete curl command. Copy it and replace the `<placeholders>`.' properties: action: { type: string, enum: [search, inspect, run, status, result, none] } call: oneOf: - type: string description: curl command against https://api.beatapi.io. - type: object required: [tool, arguments] properties: tool: { type: string, enum: [capabilities_search, capabilities_inspect, capabilities_run] } arguments: { type: object, additionalProperties: true } note: { type: string }Technical Analysis
The REST workflow instructs the agent to copy and execute a complete
curlcommand supplied in the remote API response. Although the schema describes the command as targetinghttps://api.beatapi.io, this is only descriptive text. The reviewed instructions do not require parsing the response into structured HTTP fields, checking for shell metacharacters, validating the destination, or comparing the command against a fixed endpoint allowlist.This creates a data-to-code trust-boundary violation: remotely supplied response content is promoted from data to local shell syntax. Shell operators, command substitutions, redirects, or ...[truncated 2001 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all instructions that tell an agent to execute
next.callas a complete shell command. - Construct each HTTP request locally from structured fields using a fixed HTTPS origin and a fixed endpoint allowlist.
- Use an HTTP client API rather than a shell. If a CLI is unavoidable, invoke it with an argument array and without
shell=true. - Permit only the documented capability operations and endpoints:
/v1/capabilities/search/v1/capabilities/inspect/v1/capabilities/run
- Validate that the scheme is HTTPS, the hostname exactly matches the configured and authorized BeatAPI origin, and redirects cannot forward authorization headers to another origin.
- Validate
action,reference,operation, task identifiers, request identifiers, and request bodies against local schemas before issuing a request. - Treat
next.call,next.note, and other response strings as untrusted display data only. - For MCP responses, retain the existing tool-name allowlist and additionally validate
argumentsagainst the exact schema of the selected tool. - Prefer deriving the next operation from structured response fields such as
action, task ID, and request ID rather than accepting executable instructions from the server.
- Remove all instructions that tell an agent to execute
