T09 · Insecure Skill Coding Practices
- Location
scripts/load-config.sh:18- Finding
Arbitrary Shell Command Execution Through Sourced Configuration File
- Content
View full analysis
Vulnerability Details
File Location:
scripts/load-config.sh:18-25
Vulnerability Type: Unsafe execution of configuration content
Risk Level: HighVulnerable Code
bash # Load only .env (local/private runtime config) # .env.example is template-only and must NOT be sourced at runtime. if [[ -f "$SKILL_ROOT/.env" ]]; then set -a # shellcheck disable=SC1090 source "$SKILL_ROOT/.env" set +a fiTechnical Analysis
The implementation loads
.envwith the Bashsourcecommand. This treats the file as executable shell code rather than as a declarative collection of configuration values.Consequently, an
.envfile may contain command substitutions, redirections, function definitions, pipelines, or arbitrary commands. These constructs execute wheneverload-config.shis sourced. The configuration loader is used by the main scanner throughscripts/psl-core.shand directly byscripts/analyze-log.sh, making the issue reachable through normal Skill operations.The legitimate requirement is only to read a defined set of configuration keys. Granting the configuration file full shell execution capability exceeds the minimum privilege necessary for that purpose.
Attack Path
- An attacker obtains the ability to create or modify
.envin the Skill root, such as through a compromised installation process, writable shared directory, archive extraction, or another local file-write primitive. - The attacker inserts a shell payload into
.env, for example a command substitution or standalone command. - A user or Agent invokes
detect-injection.sh,pre-action-check.sh,pre-send-scan.sh, oranalyze-log.sh. - The relevant execution path loads
scripts/load-config.sh. - Bash executes the malicious
.envcontent throughsource. - The payload runs with the operating-system permissions and environment of the invoking Agent process.
Impact Assessment
Successful ...[truncated 593 chars]
- An attacker obtains the ability to create or modify
- Remediation
View remediation
Remediation Suggestions
- Do not use
source,.,eval, or another shell evaluator to parse configuration. - Implement a strict parser that accepts only an explicit allowlist of keys, such as
PSL_MODE,PSL_RULES_DIR,PSL_LOG_PATH, and the documented rate-limit settings. - Require a simple
KEY=VALUEgrammar and reject command substitutions, backticks, shell operators, redirections, multiline values, function declarations, and unknown keys. - Validate each value after parsing:
- Restrict
PSL_MODEtostrict,balanced, orlowfp. - Parse rate-limit values as bounded positive integers.
- Restrict action flags to their documented enumerations.
- Canonicalize and constrain writable paths to approved directories.
- Restrict
- Check
.envownership and permissions before loading it, and reject files writable by untrusted users. - Add tests proving that shell syntax in
.envis rejected and never executed.
- Do not use
