T09 · Insecure Skill Coding Practices
- Location
scripts/succession.sh:28- Finding
Unquoted Argument Expansion Allows Local Filename Disclosure
- Content
View full analysis
/dev/null || true; INPUT="$*" python3 -c ' import sys cmd=sys.argv[1] if len(sys.argv)>1 else "help" inp=" ".join(sys.argv[2:]) if cmd=="plan": role=inp if inp else "Key Role" print("=" * 55) print(" Succession Plan: {}".format(role)) print("=" * 55) for section in [("Current Holder","Name: ___ Tenure: ___ Retirement/departure: ___"),("Critical Knowledge","1. ___\n 2. ___\n 3. ___"),("Successor Candidates","Primary: ___ (Readiness: Now/6mo/1yr)\n Secondary: ___ (Readiness: ___)\n External: Consider if needed"),("Development Plan","1. Mentoring with current holder\n 2. Stretch assignments\n 3. Training courses\n 4. Cross-functional exposure"),("Transition Timeline","Month 1: Shadow and observe\n Month 2-3: Co-lead responsibilities\n Month 4-6: Lead with support\n Month 7+: Fully independent")]: print("\n {}:".format(section[0])) for line in section[1].split("\n"): print(" {}".format(line.strip())) elif cmd=="matrix": print(" 9-Box Talent Matrix:") print(" Performance ->") print(" Low Med High") print(" High | Enigma | Growth Star | Future Leader |") print(" Med | Underperf | Core Player | High Potential|") print(" Low | Risk | Average | Specialist |") print(" ^ Potential") elif cmd=="help": print("Succession Planner\n plan [role] — Succession plan template\n matrix — 9-Box talent matrix") else: print("Unknown: "+cmd) print("\nPowered by BytesAgain | bytesagain.com") ' "$CMD" $INPUT ``` ### Technical Analysis The script collects all remaining command-line arguments in `INPUT` and later expands that variable without quotation: ```bash ' "$ ...[truncated 2178 chars]- Remediation
View remediation
/dev/null || true python3 -c ' # Existing Python implementation ' "$CMD" "$@" ``` `"$@"` expands each supplied argument as a distinct, quoted argument without shell word splitting or pathname expansion. Alternatively, if all remaining arguments must intentionally be passed as one string, quote the existing variable: ```bash ' "$CMD" "$INPUT" ``` The argument-array approach is preferable because it preserves the caller's original argument boundaries. Additional hardening steps: 1. Run ShellCheck in CI and treat warning `SC2086` as a failure. 2. Add regression tests using literal wildcard and whitespace-containing inputs: ```bash ./scripts/succession.sh plan '*' ./scripts/succession.sh plan 'Role with spaces' ``` 3. Verify that output contains the literal supplied value and does not contain unrelated filenames from the current directory. 4. Avoid flattening arguments through `INPUT="$*"` unless a single combined value is explicitly required. ]]>
