T09 · Insecure Skill Coding Practices
- Location
SKILL.md:67- Finding
Shell Command Injection Through Unescaped User-Controlled Template Values
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 67-76
Vulnerability Type: Shell command injection caused by unsafe textual interpolation
Risk Level: HighVulnerable Code
bash curl -X POST "https://gmapsscraper.io/api/v1/jobs" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \ -d '{ "name": "Find: {{business_type}} in {{location}}", "keywords": ["{{business_type}} in {{location}}"], "lang": "en", "depth": 2, "email": true }'Technical Analysis
The
business_typeandlocationtemplate variables originate from the user's request and are interpolated directly into a shell command. They appear inside a single-quoted shell argument without shell-safe or JSON-safe encoding.If an agent performs literal template substitution and executes the resulting command through a shell, a value containing a single quote can terminate the
-dargument. The remaining characters may then be interpreted as shell operators and commands rather than JSON data. JSON escaping alone is insufficient because shell parsing occurs beforecurlreceives the request body.This vulnerability is conditional on the documented command being instantiated through direct textual substitution and executed by a shell, which is the workflow shown by the Skill.
Attack Path
- An attacker supplies a crafted business type or location containing a single quote, shell separators, and an appended command.
- The agent parses the attacker-controlled text as
business_typeorlocation. - The agent substitutes that value literally into the documented
curlcommand. - The injected single quote closes the intended shell argument prematurely.
- The shell parses the remaining attacker-controlled text as command syntax.
- The appended command executes locally with the privileges and environment of the agent process.
Impact Assessme
...[truncated 773 chars]
- Remediation
View remediation
Remediation Suggestions
Avoid direct textual interpolation of user-controlled values into shell commands.
- Construct the request in a programming language using a standard JSON serializer.
- Invoke the HTTP client without a shell, passing each argument separately through a process API.
- If a shell example must be retained, use
jqto serialize values safely and pass user input through positional arguments or environment variables rather than embedding it into shell source. - Validate
business_typeandlocationagainst reasonable length and character constraints as defense in depth. Validation must not replace context-appropriate encoding. - Store the generated JSON in a securely created temporary file or pipe it directly to
curl; avoid predictable temporary filenames. - Add tests covering single quotes, double quotes, backslashes, command separators, command substitutions, newlines, and malformed JSON.
A safer shell pattern is:
bash payload="$( jq -n \ --arg business_type "$BUSINESS_TYPE" \ --arg location "$LOCATION" \ '{ name: ("Find: " + $business_type + " in " + $location), keywords: [($business_type + " in " + $location)], lang: "en", depth: 2, email: true }' )" || exit 1 curl --fail-with-body -X POST "https://gmapsscraper.io/api/v1/jobs" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer $GMAPS_SCRAPER_API_KEY" \ --data-binary "$payload"In this pattern, values are treated as data by
jqrather than being inserted into executable shell syntax.
