T09 · Insecure Skill Coding Practices
- Location
scripts/spotify-control.py:51- Finding
AppleScript Injection Through Unvalidated Volume and Position Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Spotify control skill is mostly coherent, but it has a real input-validation flaw that can turn volume or seek commands into unintended AppleScript execution.
Review or fix this skill before installing. It should validate volume as an integer from 0 to 100 and position as a non-negative finite number before invoking osascript; until then, only use it where you trust the agent and inputs passed to the wrapper.
scripts/spotify-control.py:51AppleScript Injection Through Unvalidated Volume and Position Arguments
The skill documentation instructs agents to use a Python wrapper and explicitly describes shell-style invocation, but the manifest declares no tool scope such as permissions or allowed-tools. This creates an authorization gap where an agent may invoke shell-capable behavior without an explicit least-privilege declaration, increasing the chance of unintended command execution or overly broad runtime access.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def run_osascript(script):
try:
process = subprocess.Popen(['osascript', '-e', script], stdout=subprocess.PIPE, stderr=subprocess.PIPE, text=True)
stdout, stderr = process.communicate()
if process.returncode != 0:
print(f"Error: {stderr.strip()}")
No suspicious patterns detected.