T09 · Insecure Skill Coding Practices
- Location
references/video_pipeline.md:58- Finding
Unsafe Shell Interpolation of Untrusted Media File Paths
- Content
View full analysis
" -vf "select=eq(pict_type\,I),scale=1280:-1" -vsync vfr -frame_pts 1 /tmp/factcheck_frames/frame_%04d.jpg -y 2>/dev/null ``` ```bash ffmpeg -i "" -vf "fps=1/10,scale=1280:-1" /tmp/factcheck_frames/frame_%04d.jpg -y 2>/dev/null ``` ```bash ffprobe -v quiet -print_format json -show_format -show_streams "" 2>/dev/null ``` The same pattern appears in the image pipeline: ```bash exiftool -json "" ``` ```bash c2patool "" ``` ### Technical Analysis `` represents a path influenced by an attached file or downloaded media. The instructions direct the Agent to substitute this value into shell command strings but do not require canonicalization, strict validation, argument-array execution, or reliable shell escaping. Wrapping a substituted value in double quotes is not sufficient if the Agent performs direct textual replacement. A filename containing a double quote followed by shell syntax can terminate the quoted argument and introduce additional commands. Filenames beginning with option characters may also be interpreted as command-line options by utilities that are not given an option terminator. The vulnerability depends on the execution layer implementing these examples through shell-string interpolation. The Skill does not provide safeguards that would prevent such an implementation. ### Attack Path 1. An attacker supplies an image or video with a crafted local filename containing quote characters and shell metacharacters. 2. The Skill routes the file to the image or video analysis pipeline. 3. Th ...[truncated 972 chars]- Remediation
View remediation
