T09 · Insecure Skill Coding Practices
- Location
minimax-coding-plan-usage.sh:6- Finding
Arbitrary Shell Execution Through Unsafe Parent Environment File Sourcing
- Content
View full analysis
Vulnerability Details
File Location:
minimax-coding-plan-usage.sh, line 6
Vulnerability Type: Unsafe execution of configuration content
Risk Level: MediumVulnerable Code:
bash source "$(dirname "$0")/../../.env"Technical Analysis
The script uses Bash
sourceto load an.envfile located two directories above the script.sourcedoes not safely parse configuration as data; it executes the entire file as shell code in the current process. Consequently, command substitutions, shell functions, redirections, and arbitrary commands placed in that file run with the privileges of the user invoking the Skill.The path also conflicts with
SKILL.md, which tells users to create.envin the same directory as the script. Traversing two parent directories unnecessarily expands the trust boundary to workspace-level configuration and exceeds the access required to obtain onlyMINIMAX_CODING_API_KEYandMINIMAX_GROUP_ID.Attack Path
- An attacker or compromised local process obtains write access to the
.envfile located two directories above the script. - The attacker inserts a shell command into that file, such as a command that copies readable credentials or modifies user-owned files.
- A user invokes
minimax-coding-plan-usage.sh. - At line 6, Bash sources the attacker-controlled file before making the MiniMax API request.
- The injected commands execute under the invoking user's identity and inherit the script's environment and accessible resources.
This path requires the attacker to influence the referenced parent
.env; the reviewed project does not itself create or modify that file.Impact Assessment
Successful exploitation permits arbitrary command execution with the invoking user's existing privileges. The attacker could read or modify files accessible to that user, access environment variables and credentials, initiate network requests, or alter user-level confi ...[truncated 448 chars]
- An attacker or compromised local process obtains write access to the
- Remediation
View remediation
Remediation Suggestions
- Do not use
source,., orevalto process an.envfile. - Resolve configuration from the documented location beside the script rather than traversing parent directories.
- Parse the file as data with a non-executing parser and strictly allowlist only
MINIMAX_CODING_API_KEYandMINIMAX_GROUP_ID. - Reject malformed variable names, duplicate entries, shell metacharacters, command substitutions, and unexpected keys.
- Verify that the configuration is a regular file, is not an unsafe symbolic link, and is not writable by untrusted users.
- Require restrictive permissions, such as owner read/write only, because the file contains an API credential.
- Prefer receiving the two values from an already-established process environment or a dedicated secrets manager.
- Update
SKILL.mdso its setup instructions and invocation example exactly match the implemented file location and script name.
- Do not use
