T09 · Insecure Skill Coding Practices
- Location
SKILL.md:34- Finding
Shell Command Injection Through Untrusted Douyin Content
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:34
Vulnerability Type: Shell command injection through unsafe interpolation of remote content
Risk Level: HighVulnerable Code:
bash python3 scripts/create_docx.py --title "标题" --author "作者" --content "完整文案" --output /tmp/output.docxTechnical Analysis
The documented workflow instructs the agent to place the title, author nickname, and full post content extracted from a remote Douyin page directly into a shell command. These values are controlled by the publisher of the referenced Douyin post and must therefore be treated as untrusted input.
Enclosing substituted content in double quotes is not sufficient when an agent constructs the final command as shell source text. Shell command substitutions such as
$(command)and backtick expressions remain active inside double-quoted shell syntax. Embedded quotation marks can also terminate the intended argument and introduce additional shell operators.For example, if remotely extracted content is inserted into the command as:
text $(attacker-controlled-command)the generated command may become:
bash python3 scripts/create_docx.py --title "标题" --author "作者" --content "$(attacker-controlled-command)" --output /tmp/output.docxThe shell evaluates the command substitution before invoking Python. The vulnerability is in the skill's command-construction instructions rather than in
scripts/create_docx.py, which processes arguments without independently invoking a shell.Attack Path
- An attacker publishes a Douyin post whose description, title, or author-controlled metadata contains shell command-substitution syntax or characters that break out of the intended quoting context.
- The attacker persuades a victim to submit that Douyin link to an agent using this skill, or the victim independently requests extraction of the malicious post.
- Foll ...[truncated 1111 chars]
- Remediation
View remediation
Remediation Suggestions
-
Do not construct shell source code by interpolating extracted titles, author names, or post content.
-
Invoke the script through a process API that accepts an argument array and disables shell processing. For example:
python subprocess.run( [ "python3", "scripts/create_docx.py", "--title", title, "--author", author, "--content", content, "--output", output_path, ], shell=False, check=True, ) -
Prefer passing potentially large post content through standard input or a securely created temporary file rather than as a command-line argument. This also avoids command-line length limits and exposure through process listings.
-
If a shell-based interface cannot be eliminated, apply a proven per-argument escaping mechanism such as
shlex.quoteto every untrusted value. Manual quote replacement or filtering selected metacharacters is insufficient. -
Generate output paths internally rather than deriving them directly from author-controlled names. If author names are included in filenames, normalize them to a strict allowlist and ensure the resolved path remains within the designated output directory.
-
Execute the extraction workflow with least privilege, restricted filesystem access, and constrained outbound networking to reduce the impact of any future command-execution flaw.
-
