T09 · Insecure Skill Coding Practices
- Location
SKILL.md:67- Finding
Shell Command Injection Through Unsafely Interpolated Search Parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 67–75
Vulnerability Type: Shell command injection caused by unsafe template interpolation
Risk Level: Highbash curl -X POST "https://gmapsscraper.io/api/v1/scrape" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \ -d '{ "keywords": ["{{keyword}} in {{location}}"], "email": true, "depth": 2 }'Technical Analysis
The
keywordandlocationvalues are collected from the user and inserted directly into a single-quoted shell argument. No shell escaping, JSON-safe serialization, or input validation is specified.A user-supplied apostrophe can terminate the single-quoted
-dargument prematurely. Subsequent shell metacharacters in the substituted value may then be interpreted by the shell rather than treated as JSON data. JSON escaping alone would not be sufficient because shell parsing occurs beforecurlreceives the request.The API key is also present in the environment used by the vulnerable command. Consequently, successful command injection could allow an injected process to access that credential and other data available to the agent process.
Attack Path
- The agent asks the user to provide a business keyword and location.
- An attacker supplies a value containing an apostrophe followed by shell syntax and a harmless verification action, such as creating a marker file.
- The agent confirms the search and substitutes the attacker-controlled value into the documented command.
- The apostrophe closes the shell argument containing the JSON body.
- The shell interprets the remaining injected syntax as commands.
- Those commands execute with the same operating-system identity, environment, filesystem access, and network permissions as the agent.
Impact Assessment
Successful exploitation can provide arbitrary command execution under the agent's curr ...[truncated 553 chars]
- Remediation
View remediation
Remediation Suggestions
Do not place template values directly into shell source. Construct the request with a JSON-aware serializer and pass the serialized body to
curlthrough standard input:bash query="${keyword} in ${location}" jq -n --arg query "$query" \ '{keywords: [$query], email: true, depth: 2}' | curl --fail-with-body --silent --show-error \ -X POST "https://gmapsscraper.io/api/v1/scrape" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \ --data-binary @-Additional hardening measures:
- Prefer direct process invocation with an argument array rather than execution through a shell.
- Treat
keywordandlocationexclusively as data and never evaluate or concatenate them into executable command text. - Apply reasonable length limits and reject control characters. Input validation should supplement, not replace, safe serialization.
- Verify that
jqis available and declare it as a required binary if the example above is adopted. - Run the skill with least privilege, a restricted filesystem, and limited outbound network access.
- Keep the API key only in the environment, redact authorization headers from logs, and rotate the key if command injection may have occurred.
- Add regression tests using apostrophes, quotation marks, command substitutions, semicolons, newlines, and other shell metacharacters to confirm they remain literal JSON data.
