T09 · Insecure Skill Coding Practices
- Location
index.js:68- Finding
Arbitrary Command Execution Through Shell Command Injection
- Content
View full analysis
Vulnerability Details
File Location:
index.js:68-75
Related Documentation Locations:SKILL.md:61-75,USAGE.md:33-47
Vulnerability Type: OS command injection through unescaped shell command construction
Risk Level: HighVulnerable Code
javascript // Build the curl command const curlCommand = `curl -X POST "https://api.xiaomimimo.com/v1/chat/completions" \ -H "api-key: ${apiKey}" \ -H "Content-Type: application/json" \ -d '${JSON.stringify(requestData)}'`; try { // Execute the curl command const { stdout, stderr } = await execPromise(curlCommand);The same unsafe shell-command construction and execution pattern is recommended in
SKILL.md:61-75andUSAGE.md:33-47.Technical Analysis
The application constructs a single shell command containing the API key and serialized request data, then executes it with
child_process.exec(). This API invokes a command shell, so shell metacharacters in interpolated values are interpreted by the shell rather than treated exclusively as data.The user-controlled query is placed in
requestData.messages[0].contentbeforeJSON.stringify(requestData)is embedded inside a shell single-quoted argument. JSON serialization only produces valid JSON; it does not perform shell escaping. In particular, a single quote in the query can terminate the shell's quoted-dargument. An attacker can then introduce shell operators, command substitutions, or additional commands.The value of
MIMO_API_KEYis also interpolated into a double-quoted shell argument. If an attacker can influence that environment variable, shell substitutions contained in it may also be evaluated.In addition, placing the API key directly in a command-line argument can expose it to other local users or monitoring tools that are permitted to inspect process command lines.
Attack Path
- An attacker supplies a crafted search query to
mimoWebSearch()...[truncated 1877 chars]
- An attacker supplies a crafted search query to
- Remediation
View remediation
Remediation Suggestions
- Replace the shell-based
curlinvocation with Node.jsfetch()orhttps.request(). Pass the API key through the HTTP headers object and the request body through the client API without involving a shell. - If an external
curlprocess is unavoidable, useexecFile()orspawn()with an explicit argument array andshell: false. Supply the serialized body as one argument rather than concatenating it into a command string. - Never interpolate user-controlled queries, environment variables, or credentials into a shell command.
- Update the examples in
SKILL.md:61-75andUSAGE.md:33-47so users do not copy the vulnerable pattern. - Avoid exposing the API key in process arguments. A native HTTPS client is preferred because headers remain inside the process and request rather than appearing in a command line.
- Validate configuration fields such as model name, token limits, temperature, keyword limits, and result limits against explicit type and range constraints. Validation is defense in depth and must not replace removal of the shell.
- Add regression tests containing single quotes, double quotes, newlines, shell separators, and command-substitution characters. Verify that all such input is transmitted as literal request content and never interpreted by a shell.
- Run the skill under a least-privileged account with restricted filesystem and network access to reduce impact if another execution flaw is introduced.
- Replace the shell-based
