T09 · Insecure Skill Coding Practices
- Location
scripts/send_file.sh:55- Finding
Unvalidated input interpolation into JSON bodies and URL query parameters
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 ;; esac ``` 3. Let `curl` encode the query parameter: ```bash SEND_URL="https://open.feishu.cn/open-apis/im/v1/messages" SEND_PAYLOAD=$(jq -n \ --arg receive_id "$RECEIVER_ID" \ --arg file_key "$FILE_KEY" \ '{ receive_id: $receive_id, msg_type: "file", content: ({file_key: $file_key} | tojson) }') SEND_RESPONSE=$(curl -sS -X POST \ --get "$SEND_URL" \ --data-urlencode "receive_id_type=$RECEIVER_TYPE" \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ --data "$SEND_PAYLOAD") ``` If `--get` conflicts with the required POST semantics in the installed `curl` version, construct the encoded query value separately or use `curl --url-query` while explicitly retaining `-X POST`. 4. Validate receiver identifiers according to the selected receiver type, including reasonable length limits and expected formats. 5. Use `set -euo pipefail` and `curl --fail-with-body --show-error` to improve failure handling and prevent silent processing of transport errors. ]]>
