T09 · Insecure Skill Coding Practices
- Location
SKILL.md:34- Finding
Arbitrary Code Execution Through Unsafe Session Label Interpolation
- Content
View full analysis
' # Retrieved from sessions_list if key in data: data[key]['label'] = '' with open(path, 'w') as f: json.dump(data, f, indent=2, ensure_ascii=False) print(f'Label set: ') " ``` The displayed English placeholders and comments above correspond to the original template's session-key and new-name placeholders. ### Technical Analysis The skill directs the agent to replace `` with the user-supplied session name inside a single-quoted Python string embedded in a `python3 -c` command. No escaping, encoding, argument passing, or validation boundary is defined. A session name containing a single quote can terminate the intended string and introduce additional Python statements. For example, a value shaped like: ```text '; __import__('os').system('id'); # ``` would cause the generated assignment to become equivalent to: ```python data[key]['label'] = ''; __import__('os').system('id'); #' ``` The injected statement is then evaluated by the Python interpreter. Because the payload can invoke `os.system`, `subprocess`, or arbitrary Python APIs, this is not limited to corrupting the JSON file; it provides a general command-execution primitive. The `` placeholder is also interpolated into executable source. Although the documented source for that value is the trusted `sessions_list` tool, it should still be treated as data rather than generated Python syntax. ### Attack Path 1. An attacker convinces a user or agent to rename a session to a specially crafted value containing a quote and injected Python state ...[truncated 1429 chars]- Remediation
View remediation
