T09 · Insecure Skill Coding Practices
- Location
scripts/get-token.sh:14- Finding
Arbitrary Shell Command Execution Through Unsafe eval Output
- Content
View full analysis
/tmp/eval-executed) ``` causes the script to emit: ```bash ZENTAO_TOKEN=$(id > /tmp/eval-executed) ``` The documented `eval` then executes the command substitution. ### Attack Path 1. An attacker controls or compromises a configured ZenTao endpoint, tampers with `~/.zentao-token.json`, or influences a relevant environment variable. 2. The attacker supplies a URL, token, or account value containing shell syntax such as command substitution or an injected newline followed by a command. 3. The user or Agent follows `SKILL.md` and runs: ```bash eval "$(bash scripts/get-token.sh)" ``` 4. `get-token.sh` prints the ma ...[truncated 634 chars]- Remediation
View remediation
