T09 · Insecure Skill Coding Practices
- Location
scripts/get_comments.sh:119- Finding
Arbitrary Python Code Execution Through Unsafe Data Interpolation
- Content
View full analysis
/dev/null || echo "") ``` ### Technical Analysis The script inserts remote document content directly into Python source supplied to `python3 -c`: ```python doc_content = '''${DOC_CONTENT}''' ``` Shell expansion occurs before Python parses the program. Consequently, `DOC_CONTENT` is treated as source text rather than as an inert data value. A document containing a triple-quote terminator followed by valid Python statements can escape the intended string literal and inject arbitrary Python code. The third command-line argument, stored in `SHOW_ALL`, is similarly inserted into a single-quoted Python expression without validation: ```python show_all = '${SHOW_ALL}' == '--all' ``` A malicious argument containing a quote and Python statements can therefore alter the generated program. Shell quoting around the outer `python3 -c` command does not prevent this issue because the expansion remains part of the Python source string. ### Attack Path #### Remote document-content path 1. An attacker gains the ability to create or edit content in a Feishu/L ...[truncated 1804 chars]- Remediation
View remediation
&2 exit 2 ;; esac ``` 4. If environment variables are used, read them only as data: ```bash DOC_CONTENT="$DOC_CONTENT" SHOW_ALL="$SHOW_ALL" \ python3 -c ' import os doc_content = os.environ.get("DOC_CONTENT", "") show_all = os.environ.get("SHOW_ALL", "") == "--all" # Continue processing without evaluating either value. ' ``` 5. A JSON-based approach is preferable for large document bodies and should avoid operating-system environment-size limits. 6. Add regression tests containing triple quotes, single quotes, backslashes, newlines, Unicode, and code-like strings. Verify that none are interpreted as Python. 7. Run the script with the least-privileged operating-system account and narrowly scoped Feishu/Lark permissions to reduce the impact of any future injection flaw. ]]>
