T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Shell Command Injection Through Unsafe File-Path Interpolation
- Content
View full analysis
/dev/null || \ docx2txt "/path/to/file.docx" 2>/dev/null || \ unzip -p "/path/to/file.docx" word/document.xml | sed 's/<[^>]*>//g' # txt 文件 cat "/path/to/file.txt" # md 文件 cat "/path/to/file.md" ``` ### Technical Analysis The Skill instructs the agent to read user-selected documents by substituting their paths into shell command templates. Document paths are attacker-controlled input, but the templates do not provide a safe argument-passing or escaping mechanism. Wrapping a substituted path in double quotes is not sufficient when command text is assembled and then interpreted by a shell. Shell constructs embedded in the resulting command, including command substitution such as `$(...)` or backticks, may still execute. An embedded quotation mark can also terminate the intended quoted argument and introduce shell operators or additional commands. This risk affects all documented extraction paths: `pandoc`, `docx2txt`, `unzip`, and `cat`. The later instruction to quote paths containing spaces or non-ASCII characters does not prevent shell injection. ### Attack Path 1. An attacker supplies a document or document path containing shell syntax, such as command substitution or an embedded quote followed by a shell operator. 2. The agent replaces the placeholder path in one of the documented command templates with the attacker-controlled value. 3. The assembled command is passed to a shell for execution. 4. The shell evaluates the injected syntax while attempting to read or extract the document. 5. The injected command executes with the operating-system permissions of the agent process. Exploitation requires the agent or its command-execution tool to construct shell command text through direct path interpolation, as directed by the Skill. ...[truncated 744 chars]- Remediation
View remediation
