T09 · Insecure Skill Coding Practices
- Location
scripts/run_full_dry_run.py:121- Finding
Shell Command Injection Through an Unescaped Creative Brief
- Content
View full analysis
None: lines = [ "#!/usr/bin/env bash", "set -euo pipefail", "", "if [[ -z \"${FREEPIK_API_KEY:-}\" ]]; then", " echo \"FREEPIK_API_KEY is required for this Freepik-first run.\" >&2", " exit 1", "fi", "", "mkdir -p ./creative-output/{assets,scenes,audio,final,manifests}", "", ] for item in commands: lines.append(f"echo \"=== {item['step']} ({item['provider']}) ===\"") lines.append(item["command"]) lines.append("") path.write_text("\n".join(lines) + "\n", encoding="utf-8") os.chmod(path, 0o755) ``` ### Technical Analysis The `--brief` command-line value is supplied by the user and passed into `build_storyboard()`. That function incorporates the brief into each scene's `visual_prompt`. `freepik_command_templates()` then places `scene['visual_prompt']` directly inside a single-quoted shell argument. Neither JSON encoding nor shell quoting is a ...[truncated 1980 chars]- Remediation
View remediation
