T09 · Insecure Skill Coding Practices
- Location
scripts/run_search.sh:31- Finding
Shell Command Injection Through Unsafe Evaluation of Shell Configuration
- Content
View full analysis
/dev/null || true)" fi # Still not set? Try .zshrc if [[ -z "$TWITTER_API_KEY" && -f "$HOME/.zshrc" ]]; then eval "$(grep -E '^export TWITTER_API_KEY=' "$HOME/.zshrc" 2>/dev/null || true)" fi ``` ### Technical Analysis The wrapper extracts text beginning with `export TWITTER_API_KEY=` from `.bashrc` or `.zshrc` and executes the extracted text using `eval`. The regular expression only validates the beginning of the line; it does not constrain the assignment value. Consequently, shell constructs embedded in the value—including command substitution, additional commands, redirections, and function invocations—are interpreted by the active shell. Reading a credential from configuration does not require arbitrary shell evaluation. For example, the following matching line executes a command when processed by the wrapper: ```bash export TWITTER_API_KEY="$(id > /tmp/twitter-search-eval-proof)" ``` The issue expands the wrapper's behavior beyond the minimum privileges required to retrieve an API key. Instead of reading a value, it creates a local command-execution channel. ### Attack Path 1. An attacker, compromised configuration-management process, or malicious package causes a matching line to be placed in `$HOME/.bashrc` or `$HOME/.zshrc`. 2. `TWITTER_API_KEY` is absent from the wrapper's current environment. 3. The user invokes `scripts/run_search.sh`. 4. `grep` selects the attacker-controlled assignment. 5. `eval` interprets command substitutions or other shell syntax ...[truncated 789 chars]- Remediation
View remediation
