T09 · Insecure Skill Coding Practices
- Location
SKILL.md:14- Finding
Shell Command Injection Through User-Controlled URL Interpolation
- Content
View full analysis
" \``` ``` The profile-analysis instructions use the same pattern: ```markdown For profile analysis with limited posts: \```text python3 ~/.openclaw/skills/content-analyzer/scripts/analyze.py "" --max 20 \``` ``` ### Technical Analysis The Skill instructs the agent to place a URL extracted from an untrusted user message directly inside a shell command. Double quotes do not provide reliable shell escaping when the inserted value can itself contain quotation marks, command substitutions, or other shell syntax. For example, a malicious input containing a value conceptually similar to: ```text https://xiaohongshu.com/explore/example"; id; # ``` could produce: ```sh python3 ~/.openclaw/skills/content-analyzer/scripts/analyze.py "https://xiaohongshu.com/explore/example"; id; #" ``` If the `exec` implementation passes this string to a shell, the injected command is interpreted separately from the intended Python invocation. The Python script's own URL parsing cannot prevent this issue because shell interpretation occurs before the script receives its arguments. Whether exploitation succeeds depends on the execution tool's argument semantics. An execution API that invokes a process directly without a shell would prevent shell metacharacter interpretation. The documented command-string pattern, however, does not require or enforce shell-free execution and therefore exposes an unsafe execution path. ### Attack Path 1. An attacker sends a messag ...[truncated 1244 chars]- Remediation
View remediation
