T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:143- Finding
Command Injection Through Unvalidated Bash Arithmetic Input
- Content
View full analysis
- Remediation
View remediation
&2 return 1 fi if (( count < 1 || count > 100 )); then echo "Count must be between 1 and 100." >&2 return 1 fi # Continue only after successful validation. } ``` Additional hardening measures: 1. Enforce an upper bound to prevent excessive CPU use and output generation. 2. Reject signs, whitespace, arithmetic operators, variable names, brackets, and command-substitution syntax rather than attempting to sanitize them. 3. Apply validation immediately after argument parsing and before every arithmetic use. 4. Add regression tests that reject values such as: - `abc` - `1+1` - `-1` - `999999999` - `x[$(command)0]` 5. Preserve `set -euo pipefail`, but do not treat it as an input-validation mechanism; it does not prevent arithmetic injection. ]]>
