T09 · Insecure Skill Coding Practices
- Location
SKILL.md:12- Finding
Command Injection Through Unsafe User Input Interpolation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 12
Vulnerability Type: Shell command injection through unsafe construction of a JSON request
Risk Level: HighVulnerable Code
bash Uses curl to trigger a n8n workflow for all things related to IoT. All requests should be a POST formatted as follows: curl -X POST http://localhost:5678/webhook/05f3f217-08b9-42de-a84a-e13f135bde73 -H "Content-Type: application/json" -d '{"chatInput": "USERS QUESTION/REQUEST", "requestType": "DETERMINED REQUEST TYPE", "sessionId":"openclaw"}'Technical Analysis
The skill instructs the agent to insert the user's question or request into a single-quoted JSON argument passed to
curl. It does not require JSON serialization, shell escaping, input validation, or execution through a shell-free argument API.If an implementation follows this template by textual substitution, a user-controlled single quote can terminate the shell argument. Subsequent shell metacharacters may then be interpreted as command syntax rather than JSON content. JSON escaping alone is insufficient because shell quoting and JSON encoding are separate security boundaries.
Although this file contains instructions rather than executable source code, the documented command is intended to be generated and executed by an agent. The vulnerability therefore becomes exploitable when the agent places prompt content directly into this template.
Attack Path
- An attacker submits an IoT-related request containing a single quote followed by shell syntax.
- The agent classifies the request and substitutes the original text into the
chatInputfield. - The single quote closes the surrounding shell-quoted JSON argument.
- The shell interprets the remaining attacker-controlled content as command syntax.
- The injected command executes under the account and environment used to run the agent or
curl.
Impact Assessment
Successful exploitat ...[truncated 628 chars]
- Remediation
View remediation
Remediation Suggestions
- Never construct the command by substituting user input into a shell command string.
- Invoke
curlthrough a process API that accepts an argument array and does not invoke a shell. - Generate the request body with a JSON serializer rather than manual string concatenation.
- If command-line tooling is required, construct the body safely with
jq, for example by passing input through--arg, and then provide the resulting JSON as one separately quoted argument. - Validate
requestTypeagainst an explicit allowlist containing onlystate,action,historical, andcalendar. - Treat
chatInputexclusively as data and prevent it from affecting command names, options, headers, URLs, or shell syntax. - Add tests using quotes, backslashes, command separators, substitutions, and newline characters to verify that hostile input remains literal JSON data.
- Correct the malformed
stateandcalendarexamples at lines 38 and 43 so implementations are not encouraged to generate invalid JSON.
