T09 · Insecure Skill Coding Practices
- Location
references/prompt-templates.md:116- Finding
Command Injection Through Unsanitized PDF Path Interpolation
- Content
View full analysis
/tmp/paper_extracted.txt` 2. If `pdftotext` returns empty/garbled (scanned PDF), tell user to provide a text-selectable PDF or paste Results text manually 3. Scan extracted text for `Results` / `Results and Discussion` / `结果` heading 4. Extract from that heading to the next major heading (`Discussion`, `4.`, `References`, etc.) 5. Print the detected Results section summary so the user can confirm 6. Proceed to Modules A–G **PDF input types handled:** - `.pdf` file attachment in webchat/desktop - Any local path to a PDF on the user's machine - If the PDF is on the user's machine (not uploaded), use `read` to find the path then `exec` with `pdftotext` ``` The expected executable form is reinforced in `tests/test-case-5.md`, lines 17–23: ```markdown ### Step 1: Extract text from the PDF Agent runs: ```bash pdftotext -layout "" /tmp/paper_extracted.txt ``` If successful, reads `/tmp/paper_extracted.txt`. ``` ### Technical Analysis The Skill explicitly instructs the Agent to pass a user-supplied or locally discovered PDF path to `exec`. It does not require argument-array execution, shell avoidance, path canonicalization, upload-root containment, or filename validation. If the implementation constructs a shell command by replacing `` with the supplied path, shell metacharacters or command-substitution syntax embedded in that path may be evaluated. Enclosing the interpolated path in double quotes does not neutralize shell substitutions such as `$()` or backticks when the resulting text is parsed by a shell. The issue is particularly significant because the Skill accepts both uploade ...[truncated 1350 chars]- Remediation
View remediation
