T09 · Insecure Skill Coding Practices
- Location
scripts/setup.sh:42- Finding
Unsafe Persistent Shell-Profile Modification Allows Command Injection
- Content
View full analysis
Vulnerability Details
File Location:
scripts/setup.sh, lines 42–50
Vulnerability Type: Persistent shell-profile command injection
Risk Level: MediumVulnerable Code
bash SHELL_RC="$HOME/.bashrc" [ -f "$HOME/.zshrc" ] && SHELL_RC="$HOME/.zshrc" ALIAS_CMD="alias cognitive-enhance='cd $DIR && $PYTHON -c \"import sys; sys.path.insert(0, \\\"$DIR\\\"); from engine import CognitiveEnhancer; b = CognitiveEnhancer(); print(\\\"Cognitive Enhancement Engine loaded. Use b.perceive(), b.memorize(), b.recall() etc.\\\"); import code; code.interact(local=dict(b=b))\"'" if ! grep -q "cognitive-enhance" "$SHELL_RC" 2>/dev/null; then echo "$ALIAS_CMD" >> "$SHELL_RC" echo " Alias 'cognitive-enhance' added to $SHELL_RC"Technical Analysis
The setup script automatically modifies the user's
.bashrcor.zshrc, even though the action is described as optional. This modification is not required to install or verify the library and persists beyond the setup process.The values of
$DIRand$PYTHONare interpolated directly into executable shell-profile content without shell-safe escaping. In particular,$DIRis derived from the package's installation path. If that path contains quotes, command substitutions, or other shell metacharacters, it can break out of the intended alias syntax and inject additional commands into the profile.The use of double quotes while constructing
ALIAS_CMDdoes not safely serialize these values for later interpretation by another shell. The generated profile entry consequently crosses two parsing boundaries: first during setup and again whenever the shell profile is loaded.Attack Path
- An attacker distributes or places the project in a directory whose path contains carefully constructed shell syntax.
- The victim follows the documented installation instruction and runs
bash scripts/setup.sh. - The script obtains the crafted directory through
BASH_SOURCE[0]and places it in$DIR. 4 ...[truncated 938 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not modify
.bashrc,.zshrc, or another startup file during the default setup process. - Print an optional alias command for the user to inspect and install manually, or require explicit confirmation before making any persistent change.
- Serialize all dynamic values using robust shell escaping, such as
printf '%q', before writing them into shell code. - Use safe runtime quoting in the generated command, including
cd -- "$DIR". - Prefer a dedicated executable wrapper in a user-selected directory over injecting an alias into a shell profile.
- If profile integration remains supported, write a clearly marked block, create a backup, use an exact marker to detect prior installation, and provide an uninstall command.
- Add automated tests using installation paths containing spaces, single quotes, double quotes, command substitutions, semicolons, and newline characters.
- Do not modify
