T09 · Insecure Skill Coding Practices
- Location
scripts/resolve_project.sh:11- Finding
Arbitrary Command Execution Through Unsafe Path Expansion
- Content
View full analysis
/tmp/resolve-project-proof)' ``` 2. The prefix check accepts the argument because it begins with `./`. 3. `eval` reparses the resulting command: ```bash echo ./$(id > /tmp/resolve-project-proof) ``` 4. The command substitution executes `id` with the privileges of the Skill process. 5. The directory validation may subsequently fail, but the injected command has already run. An attacker could replace the demonstration command with any command available to the executing account. ### Impact Assessment Successful exploitation provides arbitrary command execution with the same operating-system privileges as the process invoking the Skill. If the Skill runs under the documented root-oriented environment, the impact may include access to root-readable dat ...[truncated 276 chars]- Remediation
View remediation
/dev/null); then echo "Error: Invalid path" >&2 exit 1 fi if [ ! -d "$EXPANDED" ]; then echo "Error: Directory not found: $EXPANDED" >&2 exit 1 fi ``` Additional hardening measures: - Treat the argument exclusively as data and never evaluate it as shell source. - Use `realpath --` or `readlink -f --` to canonicalize paths. - Add the `--` end-of-options delimiter when passing user-controlled paths to commands that support it. - If projects must remain inside an approved workspace, verify that the canonical path is beneath that workspace. - Add regression tests with inputs containing `$(...)`, backticks, semicolons, pipes, redirections, spaces, and newline characters. ]]>
