T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:102- Finding
Option Injection Through the Search Term
- Content
View full analysis
}" echo "Searching for: $term" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local m=$(grep -i "$term" "$f" 2>/dev/null || true) if [ -n "$m" ]; then echo " --- $(basename "$f" .log) ---" echo "$m" | sed 's/^/ /' fi done } ``` ### Technical Analysis The value of `term` is supplied by the user and passed to `grep` without an end-of-options marker: ```bash grep -i "$term" "$f" ``` Quoting the variable prevents shell word splitting and shell metacharacter injection, but it does not prevent `grep` from interpreting a value beginning with `-` as an option. Consequently, input intended to be a search pattern can change `grep` behavior. Depending on the supplied option, an attacker can cause recursive searching, load patterns from a local file, alter matching semantics, or consume excessive system resources. This is argument or option injection rather than shell command injection; arbitrary shell commands cannot be executed directly through this code. ### Attack Path 1. An attacker influences the argument passed to `golang search`. 2. The attacker supplies a value beginning with `-`, such as a recursive-search or pattern-file option. 3. `_search` assigns that value to `term` without validating it. 4. `grep` parses the attacker-controlled value as an option instead of a search expression. 5. The resulting `grep` invocation may inspect unintended files under the process's working directory, produce misleading results, or consume excessive resources. ### Impact Assessment The injected options execute with the permissions of the user running the Skill. The flaw does not independently elevate privileges or provide arbitrary ...[truncated 255 chars]- Remediation
View remediation
/dev/null || true) ``` If regular-expression functionality is not required, use fixed-string matching to reduce ambiguity and regular-expression denial-of-service risks: ```bash local m m=$(grep -iF -- "$term" "$f" 2>/dev/null || true) ``` Additional hardening should include: 1. Rejecting empty search terms. 2. Applying a reasonable maximum input length. 3. Avoiding command substitution for potentially large output; stream matches directly where practical. 4. Testing terms beginning with `-`, including `-R`, `-f`, and `--help`, to verify that they are treated as literal data. ]]>
