T09 · Insecure Skill Coding Practices
- Location
references/fallbacks.md:45- Finding
Over-Privileged Shell Execution Recommended as a Network Fallback
- Content
View full analysis
Vulnerability Details
File Location:
references/fallbacks.md:45-50
Vulnerability Type: Command-injection risk and excessive tool privilege
Risk Level: MediumVulnerable Code Snippet
markdown ### 当 `web_fetch` 被拦或返回异常 按这个顺序考虑: 1. 换一个更容易抓取的搜索页(如 DuckDuckGo HTML) 2. 改用 `site:` 查询,让结果页更干净 3. 改用 `exec` + `curl` 抓公开搜索结果页 4. 多源交叉,避免依赖单页Equivalent
exec + curlguidance also appears at lines 13 and 63.Technical Analysis
The Skill instructs the agent to fall back from a constrained web-fetching tool to the general-purpose
exectool andcurl. Shell execution provides substantially broader capabilities than necessary for public-web retrieval.Search queries are user-controlled, and this Skill constructs URLs from those queries. The documentation does not require shell-free argument passing, destination validation, domain allowlisting, redirect restrictions, or rejection of shell metacharacters. If an agent or wrapper interpolates an attacker-controlled query or URL into a shell command, shell syntax embedded in that value could be interpreted as an additional command.
Even where command injection is avoided, unrestricted
curlcan reach arbitrary destinations, follow redirects, access internal services, or retrieve unexpectedly large responses unless explicit safeguards are applied. This violates least privilege because the declared functionality only requires controlled retrieval of public HTTPS search pages.Attack Path
- An attacker submits a search query containing shell metacharacters or a crafted destination.
- The ordinary
web_fetchpath is blocked, times out, or otherwise fails. - The agent follows
references/fallbacks.mdand switches toexec + curl. - A vulnerable integration constructs a shell command by concatenating the query or generated URL.
- The shell interprets attacker-controlled syntax, potentially executing an additional local command.
- Alter ...[truncated 916 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
exec + curlfallback and retain a constrained web-fetching API for all network retrieval. - Allow only HTTPS destinations on an explicit list of approved public search domains.
- Resolve and validate destination addresses before connecting; reject loopback, link-local, private, reserved, and cloud metadata addresses.
- Disable redirects or validate every redirect target under the same policy.
- If
curlis operationally unavoidable, invoke it directly with a fixed argument array rather than through a shell. Never concatenate a user query into a command string. - Apply strict connection and overall timeouts, response-size limits, protocol restrictions, and output-file restrictions.
- URL-encode user queries as data and validate the complete URL independently before retrieval.
- Update all equivalent recommendations at lines 13 and 63 so they cannot reintroduce the unsafe fallback.
- Remove the
