T09 · Insecure Skill Coding Practices
- Location
SKILL.md:64- Finding
Shell Command Injection Through User-Controlled Expense Fields
- Content
View full analysis
[options] ``` ### Technical Analysis The skill instructs the agent to extract the amount, category, description, and date from unrestricted natural-language input and insert those values into a shell command. The description is placed between double quotes, but the instructions do not require shell escaping, validation, or execution through an argument-array API. Double quotes alone do not safely isolate attacker-controlled shell input. A malicious description containing a double quote can terminate the intended argument, after which shell separators or substitutions can introduce additional commands. For example, if the extracted description were: ```text lunch"; id > /tmp/expense-skill-proof; # ``` naive interpolation would produce: ```bash python ".../expense_tracker.py" add --amount 35 --category other --desc "lunch"; id > /tmp/expense-skill-proof; #" --date 2026-04-09 ``` If the agent executes this generated string through a shell, the shell runs both the legitimate expense-tracker command and the injected `id` command. The Python script itself does not invoke a shell; the vulnerability is in the skill-level command-construction instructions. ### Attack Path 1. An attacker submits a natural-language expense request containing shell syntax in the description or another interpolated field. 2. The agent extracts that attacker-controlled text according to the skill instructions. 3. The agent inserts the text into the documented command template without robust shell quoting. 4. A crafted double quote terminates the intended ` ...[truncated 1105 chars]- Remediation
View remediation
