T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Shell Command Injection Through Unsafe City-Name Interpolation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18–21
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable Code
bash curl --location 'https://data.cma.cn/kbweb/home/getStationID' \ --header 'Content-Type: application/json' \ --data '{"city":"<城市名>"}'Technical Analysis
The skill directs the agent to replace the city-name placeholder with user-controlled input inside a single-quoted shell argument. It does not require validation, safe JSON serialization, or shell-safe parameter handling.
A city name containing a single quote can terminate the
--dataargument. Subsequent shell metacharacters can then introduce additional commands. JSON escaping alone would not prevent this issue because the vulnerable interpretation occurs in the command shell before the request is sent.The vulnerability is exploitable when an agent follows the documented workflow by constructing and executing the displayed Bash command through a shell using literal placeholder substitution.
Attack Path
- An attacker submits a crafted value as the requested city name.
- The value contains a single quote that terminates the shell argument, followed by shell syntax and an attacker-selected command.
- The agent substitutes the value directly for the placeholder in the documented command.
- The agent executes the resulting command through a shell.
- The shell interprets the injected syntax as a separate local command rather than as part of the HTTP request body.
- The injected command runs with the operating-system privileges and environmental access of the agent process.
A conceptual malicious city value could take the following form:
text x"}' ; attacker-controlled-command ; #Impact Assessment
Successful exploitation can provide arbitrary command execution under the account running the agent. The resulting scope depends on that account's privileges and sandbox restrictions. Potential consequences ...[truncated 582 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not construct shell command text by substituting untrusted city names into the displayed command.
- Prefer a structured HTTP client or tool that accepts the URL, headers, and JSON body as separate typed parameters without invoking a shell.
- If Bash is unavoidable, store the city name in a quoted variable and use a JSON serializer such as
jq:
bash CITY="$USER_SUPPLIED_CITY" BODY="$(jq -n --arg city "$CITY" '{city: $city}')" curl --location 'https://data.cma.cn/kbweb/home/getStationID' \ --header 'Content-Type: application/json' \ --data "$BODY"- Pass commands as argument arrays where supported and disable shell interpretation.
- Validate that the city name conforms to an appropriate length and character policy. Validation should be defense in depth and must not replace safe argument handling.
- Explicitly instruct the agent never to interpret city names as command syntax and never to use
eval, command substitution, or string-built shell commands. - Treat API responses as untrusted data and validate the returned station identifier against the expected identifier format before using it in the second request URL.
