T09 · Insecure Skill Coding Practices
- Location
SKILL.md:237- Finding
Shell Command Injection Through User-Controlled Email Arguments
- Content
View full analysis
'' [--from ] ``` ``` The examples reinforce this behavior and explicitly permit user-provided HTML to be used as given: ```markdown User: "Send email to 0x3886e06217d31998a697c5060263beafe7bdc610@moltmail.io with subject 'Test Email' and with content 'Hello this is my test email
'" → Use the subject user gave, as email content is already HTML use it as-given with `npm run send-email`. ``` ### Technical Analysis The underlying TypeScript script reads arguments from `process.argv`, which is not inherently unsafe. The vulnerability occurs at the command-construction layer prescribed by `SKILL.md`. The command template surrounds the HTML body with single quotes but does not define any escaping or safe argument-passing mechanism. If a user-controlled recipient, subject, or body contains a single quote, it can terminate the quoted argument. Additional shell metacharacters can then be interpreted by the shell rather than passed to the TypeScript program. For example, a body shaped like the following can escape the intended argument: ```text '; attacker-controlled-command; echo ' ``` This vulnerability also applies to hostile content copied from an incoming email into a reply command. Quoting an argument with single quotes is insufficient unless embedded single quotes are safely encoded, and ad hoc shell escaping remains error-prone. ### Attac ...[truncated 1347 chars]- Remediation
View remediation
