T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
Potential Shell Command Injection Through Unsanitized City Input
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–22
Vulnerability Type: Shell command injection caused by unsafe interpolation of user-controlled input
Risk Level: MediumVulnerable Code
bash # Current weather for a city (one-liner) curl -s "wttr.in/{city}?format=%l:+%c+%t+(feels+like+%f),+%w+wind,+%h+humidity" # 3-day forecast curl -s "wttr.in/{city}?format=v2" # Will it rain? curl -s "wttr.in/{city}?format=%l:+%c+%p"The same unsafe interpolation pattern is repeated in
SKILL.mdat lines 29–44.Technical Analysis
The
{city}placeholder represents location data originating from a user's weather request. The skill directs the agent to insert this value into shell commands but does not require input validation, URL encoding, or execution through a shell-free HTTP API.Quoting the URL does not make arbitrary input safe if an agent performs direct textual substitution before passing the command to a shell. A malicious value containing a closing quotation mark and shell control syntax could terminate the URL argument and introduce an additional command. Command substitutions can also remain active inside double-quoted shell strings.
For example, a crafted location structurally equivalent to:
text "; attacker_command; #could transform the generated instruction into separate shell commands if substituted literally. Exploitability depends on the invoking agent constructing and executing the documented command through a shell rather than using a structured HTTP client.
Attack Path
- An attacker submits a weather request containing a location with shell metacharacters.
- The agent extracts the attacker-controlled location as the
{city}value. - The agent directly replaces
{city}in one of the documentedcurlcommand strings. - The generated command is passed to a shell without validation or safe argument handling.
- The shell interprets the ...[truncated 753 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not construct shell command strings by interpolating user-controlled location values.
- Use a structured HTTP client that sends the destination URL without invoking a command shell.
- If
curlmust be launched, invoke it through a process API with an explicit argument array and with shell execution disabled. - URL-encode the location as a path component before constructing the request URL.
- Validate location input using a conservative allowlist appropriate for city names and airport codes. Reject control characters, quotation marks, backticks, dollar signs, command delimiters, newlines, and other shell metacharacters.
- Use an explicit HTTPS endpoint, such as
https://wttr.in/, rather than relying on implicit protocol behavior. - Add a warning to the skill instructions stating that
{city}must never be substituted directly into a shell command. - Apply runtime restrictions to the agent process, including minimal filesystem permissions, limited environment exposure, and constrained outbound network access, to reduce the impact of any command-execution flaw.
