T09 · Insecure Skill Coding Practices
- Location
scripts/sushiro:84- Finding
jq Program Injection Through User-Controlled Store Filters
- Content
View full analysis
0))' filter+=' | sort_by(-(.wait // 0))' [[ $limit -gt 0 ]] && filter+=" | .[0:$limit]" if [[ "$format" == json ]]; then echo "$data" | jq "$filter" return fi echo "$data" | jq -r "$filter | ( ``` ### Technical Analysis The `--city` and `--area` arguments are inserted directly into a dynamically constructed jq program. The values are placed between jq string delimiters without escaping and are subsequently passed to `jq` as executable filter source. An attacker can include quote characters, closing parentheses, jq operators, and a comment marker in an argument. This allows the attacker to terminate the intended string and inject an arbitrary jq expression. For example, a malicious city value shaped as: ```text x")) | env # ``` transforms the intended expression into the equivalent of: ```jq . | map(select(.nameKana == "x")) | env # ... ``` The jq `env` built-in exposes the environment inherited by the script. The comment marker suppresses the remaining generated jq expression. Although this issue does not directly provide shell command execution, it allows execution of attacker-selected jq logic and access to data available to the jq process. This is especially relevant when an AI Agent translates untrusted natural-language content into command-line filters. An attacker could place the payload in a requested city or area name and induce the Agent to invoke the vulnerable command. ### Attack Path 1. ...[truncated 1277 chars]- Remediation
View remediation
0)) ) | sort_by(-(.wait // 0)) ' ``` Additional hardening should include: 1. Validate `--limit` as a bounded non-negative integer before using it. 2. Validate `--near` as exactly two finite numeric coordinates in valid latitude and longitude ranges. 3. Keep jq source static and supply every dynamic value through `--arg`, `--argjson`, or `--slurpfile` as appropriate. 4. Add regression tests containing quotes, closing parentheses, pipes, interpolation syntax, and jq comment markers. 5. Avoid returning raw command output to an Agent response without applying secret redaction. ]]>
