T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:64- Finding
Unescaped User-Controlled Data in JSON and CSV Exports
- Content
View full analysis
> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" echo "\n]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f" done ``` A representative path through which user-controlled data reaches these export operations is: ```bash # scripts/script.sh:126-132 local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/configure.log" local total=$(wc -l < "$DATA_DIR/configure.log") echo " [Rag Evaluator] configure: $input" echo " Saved. Total configure entries: $total" _log "configure" "$input" ``` Equivalent input-storage logic is repeated for the other domain commands. ### Technical Analysis Command arguments are stored in log files without validation and later inserted directly into JSON and CSV output. For JSON exports, quotation marks, backslashes, control characters, and embedded newlines are not JSON-escaped. An attacker can therefore terminate the intended string and inject additional JSON properties or objects, or simply produce invalid JSON. For CSV exports, fields are not enclosed and escaped according to CSV rules. Commas, quotation marks, and newlines can alter the exported row structure. More importantly, values beginning with spreadsheet formula characters such as `=`, `+`, `-`, or `@` remain active. When the CSV is opened in a spreadsheet application, the value may be evalua ...[truncated 2109 chars]- Remediation
View remediation
