T09 · Insecure Skill Coding Practices
- Location
examples/lobster-migration.yaml:39- Finding
Shell Command Injection Through Unvalidated Pipeline Arguments
- Content
View full analysis
&1 retry: maxAttempts: 2 ``` `examples/multi-agent-dev.yaml:188-205`: ```yaml - id: create-pr type: run description: Create pull request run: | cd ${args.repo} && \ git checkout -b feat/$(echo "${args.feature}" | tr ' ' '-' | tr '[:upper:]' '[:lower:]') && \ git add -A && \ git commit -m "feat: ${args.feature}" && \ gh pr create --title "feat: ${args.feature}" --body "$(cat <<'EOF' ## Summary ${args.feature} ## Architecture ${architect.json.summary} ## Review ${reviewer.json.summary} EOF )" when: $deploy-approval.approved ``` `examples/simple-deploy.yaml:19-45`: ```yaml steps: - id: build type: run run: docker build -t ${args.image} . retry: 2 - id: test type: run run: docker run --rm ${args.image} npm test retry: maxAttempts: 3 backoff: fixed delayMs: 5000 - id: approve type: gate gate: "Deploy ${args.image} to ${args.env}?" - id: deploy type: run run: kubectl set image deployment/myapp app=${args.image} -n ${args.env} when: $approv ...[truncated 3347 chars]- Remediation
View remediation
