T09 · Insecure Skill Coding Practices
- Location
agent.py:48- Finding
Shell-Enabled Editor Invocation May Permit Command Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent, but it automatically writes a project file and opens an editor through an unsafe command pattern that could run unintended commands.
Review before installing. The skill's basic workflow is understandable, but it should remove shell=True, validate or constrain project_path, avoid overwriting requests.txt without confirmation, and ask before launching an external editor.
agent.py:48Shell-Enabled Editor Invocation May Permit Command Injection
This duplicate finding flags the same underlying issue: shell-based process creation with a user-influenced argument. Because the skill automatically opens the generated file after writing it, exploitation could chain from path manipulation directly into arbitrary command execution in the host environment.
try:
# 尝试直接调用
subprocess.Popen([editor_path, file_path], shell=True)
print(f"✅ 已用 {editor_name} 打开")
except Exception as e:
# fallback 到系统默认
This duplicate finding flags the same underlying issue: shell-based process creation with a user-influenced argument. Because the skill automatically opens the generated file after writing it, exploitation could chain from path manipulation directly into arbitrary command execution in the host environment.
try:
# 尝试直接调用
subprocess.Popen([editor_path, file_path], shell=True)
print(f"✅ 已用 {editor_name} 打开")
except Exception as e:
# fallback 到系统默认
The skill instructions, triggers, and examples are entirely presented in Chinese, including the directive to describe requirements in natural language, without indicating that other languages are supported or that Chinese is an opt-in choice. This can constitute a language/locale policy issue because the skill appears to impose a specific language without user choice or justification.
The trigger conditions are broad enough to match many ordinary coding requests, which can cause the skill to activate unexpectedly instead of only when the user explicitly wants this workflow. In this skill, unexpected activation is more dangerous because the documented behavior includes writing a file into the current project directory and opening an editor automatically, creating side effects without clear user opt-in.
The skill performs side-effecting actions by writing requests.txt to the current project directory and automatically opening an editor, but it does not clearly warn the user before those actions occur. This is dangerous because users may invoke the skill expecting only text generation, while the skill modifies the workspace and launches applications, which can disrupt workflows or affect sensitive repositories.
The natural-language description and docstrings present the skill as Chinese-only, which can amount to a language policy violation when no user opt-in or locale justification is provided. There is no indication that the skill is region-specific or that users may choose another language.
This code performs a file write operation by creating or overwriting requests.txt in the specified project path. Although the module docstring mentions generating the file, the write happens without an in-flow confirmation prompt or explicit warning at the point of action, which can affect user data in the workspace.
The code launches a subprocess with shell=True while incorporating a file path derived from user-controlled project_path. On Windows in particular, shell invocation can reinterpret special characters and cause command injection or unexpected command execution, making this more dangerous than a normal editor launch.
try:
# 尝试直接调用
subprocess.Popen([editor_path, file_path], shell=True)
print(f"✅ 已用 {editor_name} 打开")
except Exception as e:
# fallback 到系统默认
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
os.startfile(file_path) # Windows
except:
subprocess.Popen(["xdg-open", file_path]) # Linux
def run(task: str, project_path: str = ".") -> str:
No suspicious patterns detected.