T09 · Insecure Skill Coding Practices
- Location
agents/main/agent.yaml:18- Finding
Shell Command Injection Through Raw Agent Input Interpolation
- Content
View full analysis
Vulnerability Details
File Location:
agents/main/agent.yaml, lines 18–21
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable Code
yaml steps: - name: run_task run: | python3 scripts/run_task.py "{{input}}"Technical Analysis
The agent entrypoint directly interpolates attacker-controlled
{{input}}into a shell command. Wrapping the value in double quotes does not neutralize shell metacharacters that remain active inside double-quoted strings, particularly command substitution expressions such as$(...)and backticks.If the agent platform renders this template and executes the resulting
runblock through a shell, malicious input can cause the shell to execute an injected command beforescripts/run_task.pystarts. The Python script's URL parsing does not mitigate the flaw because shell evaluation occurs before Python receives its arguments.For example, an input containing a valid task followed by a command substitution expression could cause the embedded command to execute during shell expansion.
Attack Path
- An attacker submits a crafted Skill request containing shell command substitution syntax, such as
$(attacker_command). - The platform substitutes the complete request into
{{input}}. - The rendered
runblock is passed to a shell. - The shell evaluates the command substitution despite the surrounding double quotes.
- The injected command runs with the privileges and environment of the agent runner.
- The shell then invokes
scripts/run_task.pywith the expanded command output as part of its argument.
Impact Assessment
Successful exploitation provides arbitrary command execution under the operating-system identity used by the Skill runner. Depending on the runner's permissions and isolation controls, an attacker could:
- Read files and environment variables accessible to the runner.
- Modify or delete accessible files.
- Execute installed programs and scri ...[truncated 448 chars]
- An attacker submits a crafted Skill request containing shell command substitution syntax, such as
- Remediation
View remediation
Remediation Suggestions
- Do not place raw user input into shell command text.
- Configure the agent platform to invoke the executable with an argument array, passing
{{input}}as one opaque argument without a shell. - If direct argument-array execution is unavailable, pass the request through standard input or a dedicated environment variable and read it from Python.
- Prefer a structured request format with explicit fields such as
modeandtargetrather than forwarding unrestricted natural-language input to a command template. - Apply strict validation to structured fields after safe transport. Restrict modes to an allowlist and validate target schemes and locations according to the intended threat model.
- Do not rely on double quotes or custom character replacement as a substitute for avoiding shell interpretation.
- Add a regression test using command-substitution characters and verify that no injected command is executed.
A safer conceptual invocation is an argv-based execution equivalent to:
python subprocess.run( ["python3", "scripts/run_task.py", user_input], shell=False, check=True, )The platform configuration must preserve
user_inputas one argument rather than first composing and evaluating a shell command.
