T09 · Insecure Skill Coding Practices
- Location
moltbook_trust.py:39- Finding
Shell Command Injection Through Moltbook Usernames
- Content
View full analysis
' to create one") return link = bridge["links"][username] print(f"Moltbook User: {username}") print(f" Fingerprint: {link['fingerprint']}") print(f" Linked: {link['linked_at']}") print(f" Verified: {'✓' if link.get('verified') else '✗ (unverified)'}") # Get ATP trust score score_out = atp_cmd(f"trust score {username}") if score_out: print(f" ATP Trust: {score_out}") def cmd_score(username, domain=None): """Get trust score for a Moltbook user.""" bridge = load_bridge() if username not in bridge["links"]: print(f"✗ Unknown user: {username}") return domain_flag = f" --domain {domain}" if domain else "" score_out = atp_cmd(f"trust score {username}{domain_flag}") ``` The leaderboard also passes stored usernames to the same shell sink: ```python for username, link in bridge["links"].items(): score_out = atp_cmd(f"trust score {username}") ``` ### Technical Analysis `atp_cmd()` builds a shell command by interpolating an untrusted string and executes it with `shell=True`. The shell t ...[truncated 2258 chars]- Remediation
View remediation
