T09 · Insecure Skill Coding Practices
- Location
SKILL.md:237- Finding
Shell Command Injection Through Unsafe Cron Command Construction
- Content
View full analysis
" \ --session isolated \ --message "执行定时打车:起点「」,终点「」,车型「」。请完整执行打车流程:地址解析 → 价格预估(获取最新 traceId)→ 创建订单。订单创建成功后,输出订单信息并提示用户可发送「查询订单」了解订单状态,同时创建 5 分钟后自动回查 cron(模板见 SKILL.md 第 3.8 节「发单后自动回查」)。" \ --announce \ --channel \ --to "" ``` The same pattern is used for automatic order checks: ```bash openclaw cron add \ --name "didi-ride-skill:check:" \ --at "5m" \ --session isolated \ --message "查询滴滴订单状态:订单号 。调用 taxi_query_order 查询并输出当前状态。如果司机已接单,输出司机姓名、车型、车牌、电话及预计到达时间;如果仍在匹配中,提示用户耐心等待。" \ --announce \ --channel \ --to "" ``` ### Technical Analysis The instructions require placeholders such as `FROM_NAME`, `TO_NAME`, `VEHICLE`, `ORDER_ID`, `CHANNEL_NAME`, and `CHAT_ID` to be replaced with actual values before executing a shell command. Several of these values can originate from user input, external API results, or session metadata. The values are interpolated directly into shell syntax without an allowlist or shell-safe argument encoding. Double quotes do not make a command safe when the Agent constructs the final command text by inserting attacker-controlled shell metacharacters. For example, if a location is inserted as `Station $(attacker_command)`, the generated command contains active command-substitution syntax that the shell can evaluate. Characters such as command substitutions, backticks, embedded quotes, newlines, redirection operators, and argument separators may therefore alter the intended command. The scheduled task message can also be modified to inject unintended instructions into the ...[truncated 1387 chars]- Remediation
View remediation
