T09 · Insecure Skill Coding Practices
- Location
SKILL.md:75- Finding
Shell Command Injection Through Unsanitized Task, Path, and Request Values
- Content
View full analysis
rev-parse --abbrev-ref HEAD) # Create worktree TASK= # 2-3 words, kebab-case, from request git -C worktree add ~/.worktrees/$TASK -b feat/$TASK # Create supervisor directory for wake markers mkdir -p ~/.worktrees/$TASK/.supervisor ``` The same workflow embeds request-controlled text directly into a shell command: ```bash bash pty:true workdir:~/.worktrees/$TASK background:true command: claude -p "Context: Request: Instructions: - Research the codebase and relevant best practices - Design the architecture following the Engineering Practices in your system prompt - Produce a detailed implementation plan with test strategy - Wrap plan in [PLAN_START] and [PLAN_END] - Do NOT execute yet" \ --output-format json \ --dangerously-skip-permissions \ --allowedTools "Read,Glob,Grep,LS,WebSearch,WebFetch,Bash(git log *,git diff *,git show *,git status,git branch --list *)" \ --append-system-prompt-file "$SUPERVISOR_PROMPT" ``` ### Technical Analysis The workflow derives `TASK` from the user's request and uses it in shell paths and Git branch names without specifying mandatory validation, escaping, or safe argument-array construction. The project directory and original request are also represented as direct substitutions into shell commands. In particular, the original request is inserted inside a double-quoted `claude -p` argument. Shell metacharacters that remain meaningful inside double quotes, such as command substitutions using `$(...)` or backticks, may be evaluated by the shell. An embedded quote can also terminate the intended argument and introduce additional shell syntax. Unquot ...[truncated 1814 chars]- Remediation
View remediation
