T09 · Insecure Skill Coding Practices
- Location
scripts/setup.sh:33- Finding
Command Injection Through Executable Configuration File
- Content
View full analysis
> "$CONFIG_DIR/config" read -p "Paste the parent page ID: " parent_page echo "NOTION_PARENT_PAGE=$parent_page" >> "$CONFIG_DIR/config" read -p "Paste your Todoist API token: " todoist_key echo "TODOIST_API_KEY=$todoist_key" >> "$CONFIG_DIR/config" ``` `scripts/status.sh:12` subsequently executes the configuration file in the current shell: ```bash source "$CONFIG" ``` ### Technical Analysis The setup script treats API credentials and page identifiers as data but serializes them as unquoted shell expressions. The status script then uses `source`, which treats every line in the file as executable shell code. Shell metacharacters and command substitutions contained in a supplied value are written literally to the configuration file. When the file is later sourced, those expressions are evaluated. For example, a token entered as: ```bash $(malicious_command) ``` can produce a configuration entry such as: ```bash TODOIST_API_KEY=$(malicious_command) ``` The command executes when `status.sh` sources the file. An attacker who can modify `~/.config/4to1/config` can also insert arbitrary shell statements directly. Configuration parsing does not require code execution. This behavior exceeds the minimum privileges needed to read backend settings and test API connectivity. ### Attack Path 1. An attacker convinces the user to enter a crafted API token or Notion page identifier during setup, or gains write access to `~/.config/4to1/config`. 2. `scripts/setup.sh` stores the attacker-controlled value as unquoted shell synt ...[truncated 866 chars]- Remediation
View remediation
