T09 · Insecure Skill Coding Practices
- Location
skill.json:34- Finding
Command Injection Through Unquoted Tool Parameters
- Content
View full analysis
- Remediation
View remediation
- --language - ``` Add `--summary` as a separate argument only when requested. Apply the same approach to `--task-status`. 2. **Validate task IDs.** Require `task_id` to match canonical UUID syntax, such as: ```regex ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-5][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}$ ``` 3. **Restrict language values.** Use a schema enumeration containing only language codes supported by `GeodeCLI`, rather than accepting an arbitrary string. 4. **Validate and canonicalize audio paths.** Require an absolute path, resolve symbolic links where appropriate, verify that the target exists and is a regular readable file, and optionally restrict it to the documented App Group inbox. 5. **Use framework-native escaping only as a fallback.** If the platform cannot avoid command strings, apply its documented shell-escaping mechanism independently to every interpolated parameter. Adding literal quotation marks alone is insufficient unless embedded quotes and command substitutions are safely escaped. 6. **Add security tests.** Test spaces, quotation marks, semicolons, command substitutions, pipelines, redirections, newlines, and leading hyphens in all string parameters. Verify that each value reaches `GeodeCLI` as exactly one literal argument and cannot create additional commands or options. ]]>
