T09 · Insecure Skill Coding Practices
- Location
SKILL.md:228- Finding
Arbitrary Shell Command Execution Through Sourced Environment File
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:228-229
Vulnerability Type: Unsafe evaluation of an environment file as shell code
Risk Level: HighVulnerable code:
bash source /path/to/.env node scripts/register.mjs --json /tmp/registration.json --chain 8453 --yesTechnical Analysis
The registration instructions use the shell built-in
sourceto load.env. This does not parse the file as a passive collection of key-value pairs; it evaluates every line as shell syntax in the current process.Consequently, a malicious or compromised
.envcan contain command substitutions, functions, redirections, or arbitrary commands. These execute before the registration script starts and with the same operating-system privileges as the agent process or user running the workflow.This risk is especially relevant because the Skill explicitly directs the agent to inspect and use
.envduring its normal registration flow. The following--yesoption also bypasses the script's own interactive transaction confirmation, although the Skill separately requires explicit confirmation through chat.Attack Path
- An attacker, compromised dependency, or untrusted project modifies the
.envfile accessible to the registration workflow. - The attacker inserts shell syntax, for example:
bash PRIVATE_KEY=0x... MALICIOUS_VALUE="$(attacker-controlled-command)" - A user asks the agent to perform ERC-8004 registration.
- The agent follows
SKILL.mdand runssource /path/to/.env. - The command substitution or other injected shell statement executes before
register.mjs. - The malicious command operates with the permissions of the agent process and can access resources available to that account.
Impact Assessment
Successful exploitation provides arbitrary command execution under the account running the Skill. Depending on that account's permissions, an attacker could:
...[truncated 585 chars]
- An attacker, compromised dependency, or untrusted project modifies the
- Remediation
View remediation
Remediation Suggestions
- Remove the
source /path/to/.envinstruction and never evaluate environment files as shell programs. - Load
.envas data with a pinned environment-file parser, such as Node.js environment-file support or a reviewed and locked dotenv dependency. - Allow only the expected variable names:
PRIVATE_KEYAGENT_PRIVATE_KEYMAIN_WALLET_PRIVATE_KEYRPC_URLCHAIN_IDPINATA_JWT
- Validate every value before use:
- Require private keys to match the expected hexadecimal length and format.
- Restrict
CHAIN_IDto supported numeric values. - Require
RPC_URLto use an approved HTTPS endpoint or obtain explicit approval for a custom endpoint. - Reject control characters, newlines, and malformed entries.
- Pass validated variables directly to the Node.js process rather than exporting an entire untrusted file into the shell environment.
- Prefer retaining the script's interactive confirmation instead of using
--yes. If automation requires--yes, ensure the chat confirmation is bound to the exact chain, contract addresses, wallet, metadata, and transaction action that will be submitted. - Document that
.envmust have restrictive filesystem permissions and must never be accepted from an untrusted project without validation.
- Remove the
