T09 · Insecure Skill Coding Practices
- Location
scripts/analyze.js:40- Finding
Shell Command Injection Through Unsanitized CLI Arguments
- Content
View full analysis
/tmp/skill-command-output # ``` 3. `parseArgs()` stores this text in `options.symbol`. 4. `runAnalysis()` concatenates the value into the shell command. 5. `execSync()` invokes the shell, which runs the intended Python process and then the injected command. 6. The injected command executes with the same operating-system privileges, environment variables, filesystem access, and network access as the Skill process. ### Impact Assessment Successful exploitation provides arbitrary command execution under the account running the Agent. An attacker could: ...[truncated 483 chars]- Remediation
View remediation
