T09 · Insecure Skill Coding Practices
- Location
clawnema.ts:135- Finding
Backend-Controlled Values Are Interpolated into a Wallet Payment Command
- Content
View full analysis
\`\n\n` + `The TX hash will be in the JSON output (look for \`transactionHash\` or \`hash\` field).`; ``` ### Technical Analysis The wallet address and ticket price originate from the backend `/now-showing` response. That response is cast to `any`, and the `Theater` interface supplies compile-time types only; it does not validate the received values at runtime. Both values are inserted directly and without quoting into a shell command: ```bash npx awal@latest send --json ``` A compromised or malicious backend could return shell metacharacters in either field. If an Agent or user executes the generated command through a shell, those metacharacters could alter the command or append another command. The wallet allowlist check is not enforced. When th ...[truncated 1433 chars]- Remediation
View remediation
