Back to skill

Security audit

Wiener Linien

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Vienna public transit helper that queries public Wiener Linien data, with one limited input-handling issue in its stop search script.

Reasonable to install for Vienna transit lookups. Use normal stop names, line names, and stop IDs as inputs; the publisher should harden search-stop.sh with grep -iF -- "$QUERY" to avoid option or regex surprises.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
search-stop.sh:7
Finding

User-Controlled grep Option Injection in Stop Search

Content
View full analysis

Vulnerability Details

File Location: search-stop.sh, lines 7–18
Vulnerability Type: User-controlled command option injection
Risk Level: Medium

Vulnerable Code

bash
QUERY="${1:-}"

if [ -z "$QUERY" ]; then
    echo "Usage: $0 <stop-name>"
    echo "Example: $0 stephansplatz"
    exit 1
fi

echo "Searching for stops matching: $QUERY"
echo "---"
echo "StopID;DIVA;StopText;Municipality;Longitude;Latitude"
curl -s "https://www.wienerlinien.at/ogd_realtime/doku/ogd/wienerlinien-ogd-haltepunkte.csv" | grep -i "$QUERY" | head -20

Technical Analysis

The stop name is passed to grep without an option terminator. Shell quoting prevents shell metacharacters in QUERY from being evaluated as shell syntax, but it does not prevent grep from treating a value beginning with - as a command-line option.

For example, an argument in the form -f/path/to/file can direct grep to load patterns from a local file. The input is also interpreted as a regular expression even though the documented operation is a stop-name search. This permits unintended matching behavior and potentially expensive regular-expression processing.

This is argument injection into grep, not arbitrary shell-command injection: the vulnerable code does not use eval, an unquoted shell expansion, or a nested shell.

Attack Path

  1. An attacker or untrusted caller supplies a crafted stop-name argument beginning with a valid grep option.
  2. The agent or user invokes search-stop.sh with that argument.
  3. The script expands the argument as grep -i "$QUERY".
  4. grep interprets the crafted value as an option rather than a search pattern.
  5. Depending on the option, grep may read an attacker-selected local file as a pattern source, alter matching behavior, emit errors, or consume additional resources.
  6. The resulting patterns are applied to the public Wiener Linien CSV stream, and matching CSV lines may be ...[truncated 608 chars]
Remediation
View remediation

Remediation Suggestions

Terminate option parsing and use fixed-string matching because the documented input is a literal stop name:

bash
curl -fsS \
  "https://www.wienerlinien.at/ogd_realtime/doku/ogd/wienerlinien-ogd-haltepunkte.csv" |
  grep -iF -- "$QUERY" |
  head -20

Security hardening should include:

  1. Use -- before the query so values beginning with - cannot be parsed as options.
  2. Use -F to disable regular-expression interpretation and perform a literal stop-name search.
  3. Use curl -fS so HTTP failures are reported rather than silently passed to the parser.
  4. Consider adding a reasonable query-length limit to reduce resource-abuse risk.
  5. Add regression tests for inputs such as -f/etc/passwd, --help, regex metacharacters, spaces, and non-ASCII stop names.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.