T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Untrusted Runbook Content Can Be Converted into Executable Shell Commands
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18-76 and 138-143
Vulnerability Type: Untrusted command generation and potential command injection
Risk Level: HighVulnerable Code
markdown ### 1. `convert` — Parse Runbook and Generate Automation #### Step 1: Identify Runbook Format Read the input runbook (markdown, Confluence wiki, Google Doc, plain text) and extract: - **Title and scope** — what incident does this address - **Prerequisites** — access, tools, permissions needed - **Steps** — ordered actions (distinguish manual vs automatable) - **Decision points** — if/then branches - **Verification steps** — how to confirm each step worked - **Rollback steps** — how to undo if things go wrong - **Escalation criteria** — when to page someone #### Step 2: Classify Each Step For each step in the runbook, classify as: | Type | Example | Automation | |------|---------|------------| | **Command** | "Run `kubectl rollout restart`" | Direct script execution | | **Check** | "Verify pods are running" | Script with assertion | | **Decision** | "If error rate > 5%, proceed to step 4" | Conditional branch | | **Manual** | "Call the database team" | Notification + pause | | **Observation** | "Watch the dashboard for 10 minutes" | Timed wait + metric check | #### Step 3: Generate Executable Playbook ```bash # --- Step 1: [Name] --- step_1() { log "Step 1: [description]" if [[ "$DRY_RUN" == "true" ]]; then log "DRY RUN: would execute [command]" return 0 fi # [actual command] [command] || fail 1 "[error description]" # Verify [verification command] || fail 1 "Verification failed" log "Step 1: ✅ Complete" }3.
test— Dry-Run a Generated PlaybookExecute the generated script with
DRY_RUN=true:- Validate all commands exist in PATH
- Check prerequisite access (can reach hosts, have credentials)
- Verify notification h ...[truncated 3658 chars]
- Remediation
View remediation
Remediation Suggestions
-
Treat all source documents as untrusted input
- Explicitly state that commands copied from runbooks must never be executed or emitted as trusted code without validation.
- Record the source, owner, revision, and trust status of each imported runbook.
-
Require command-by-command human approval
- Present every generated command, verification command, and rollback command for review.
- Require explicit confirmation before producing an executable artifact or performing a non-dry-run execution.
- Highlight commands involving privilege changes, credentials, network transfers, destructive operations, or persistence.
-
Use structured command representations
- Represent each operation as an executable plus a separate argument array rather than interpolated shell text.
- Avoid
eval,bash -c, command substitution, and direct insertion of document content into shell scripts. - Generate code using safely quoted arguments and fixed templates.
-
Enforce restrictive validation and allowlists
- Allow only approved executables and documented argument patterns.
- Reject or require elevated review for shell control operators, redirections, pipes, command substitutions, multiline commands, encoded payloads, and unexpected network destinations.
- Validate resource names, hostnames, file paths, URLs, and metric values against strict schemas.
-
Add mandatory policy checks
- Scan generated playbooks for destructive commands, credential access, external uploads, persistence mechanisms, privilege escalation, and shell-injection patterns.
- Fail closed when a command cannot be classified or safely parsed.
- Require rollback and verification steps to pass the same security checks as primary commands.
-
Execute in a least-privileged sandbox
- Use an isolated container or dedicated runner with a read-only filesystem where possible.
- Pro ...[truncated 756 chars]
-
