T09 · Insecure Skill Coding Practices
- Location
scripts/ecs-health.sh:225- Finding
Python Code Injection Through Interpolated Environment Configuration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its ECS monitoring purpose, but its scripts contain unsafe input handling that could let crafted configuration or arguments run commands in the user's AWS-enabled environment.
Review before installing. Use only with trusted configuration and command arguments, run it with least-privilege AWS read permissions, and keep output paths in a protected directory. The unsafe Python interpolation, arithmetic parsing, and temporary-file handling should be fixed before use in shared, automated, or user-facing agent environments.
scripts/ecs-health.sh:225Python Code Injection Through Interpolated Environment Configuration
scripts/cloudwatch-logs.sh:348Python Code Injection Through the Configurable Health-State Path
scripts/cloudwatch-logs.sh:87Shell Command Execution Through Unvalidated Arithmetic Input
scripts/cloudwatch-logs.sh:394Predictable Temporary File Enables Symlink-Based File Overwrite
scripts/ecs-health.sh:225Health Check Enumerates Unrelated Regional ALB Target Groups
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Referenced artifact was not completely inspected
### `scripts/cloudwatch-logs.sh` — Log Analyzer
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# Read the services list
local svc_list
svc_list=$(cat /tmp/ecs-ad-svcs.$$ 2>/dev/null)
rm -f /tmp/ecs-ad-svcs.$$
if [[ -z "$svc_list" ]]; then
return 0
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
mkdir -p "$OUTDIR"
# Dependencies check
for cmd in curl aws python3; do
if ! command -v "$cmd" &>/dev/null; then
echo "Missing dependency: $cmd" >&2
exit 2
The skill advertises and documents shell execution plus environment, file read, and file write capabilities, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens containment and review because a host may grant broader execution than operators expect, enabling AWS CLI access, network probes, and local file writes without clear policy declaration.
The script creates an output directory and later reads and manages health/log-related files under that path, which means service log data may be persisted locally. Although the header documents the output directory variables, it does not clearly warn users that potentially sensitive CloudWatch log contents may be stored on disk.
The manifest centers this skill on ECS/ALB/SSL health monitoring and CloudWatch log analysis, but this script's primary purpose is log pulling/analyzing. The auto-diagnose path adds a filesystem-based capability that parses an external health snapshot file and uses it to decide what services to inspect, which is not directly part of log analysis itself.
The script writes service information to a predictable temporary file path in /tmp using only the process ID, which is not a secure temporary-file pattern. On a multi-user system, another local user could race, pre-create, or replace that path with a symlink or file to influence behavior, expose service data, or interfere with file deletion.
No suspicious patterns detected.