T09 · Insecure Skill Coding Practices
- Location
--config '<json>' ``` ``` ### Technical Analysis The workflow instructs the Agent to construct shell commands by substituting file paths, output paths, and generated JSON directly into command templates. The file and output path placeholders are not quoted. Although the JSON placeholder is surrounded by single quotes, user-controlled values such as chart titles can contain a single quote and terminate that quoting context. If the Agent executes these templates through a shell, shell metacharacters in a c ...[truncated 1488 chars]:106- Finding
Shell Command Injection Through Unquoted File Paths and JSON Arguments
- Content
View full analysis
``` ``` ```markdown ### Inspect data (planning only) ```bash node tools/chart_renderer.js --info ``` ### Render a chart ```bash node tools/chart_renderer.js --config '' [--output ] ``` ``` ```markdown ### Step 2 — Render Charts **Immediately render all planned charts** — do NOT ask for confirmation first. For each chart, call the tool: ```bash node tools/chart_renderer.js --config '' ``` ``` ### Technical Analysis The workflow instructs the Agent to construct shell commands by substituting file paths, output paths, and generated JSON directly into command templates. The file and output path placeholders are not quoted. Although the JSON placeholder is surrounded by single quotes, user-controlled values such as chart titles can contain a single quote and terminate that quoting context. If the Agent executes these templates through a shell, shell metacharacters in a crafted filename, output path, or chart configuration can be interpreted as command separators, substitutions, or redirections rather than literal argument content. The JavaScript CLI itself does not invoke a shell, but the documented Agent workflow creates the vulnerable command-construction boundary. ### Attack Path 1. An attacker supplies a spreadsheet with a filename containing shell metacharacters, or requests a chart title/output path containing a quote followed by shell syntax. 2. The Agent substitutes that value into one of the documented command templates. 3. The resulting command is passed to a shell-based execution tool. 4. The crafted value breaks out of its intended argument context. 5. The she ...[truncated 652 chars]- Remediation
View remediation
