T09 · Insecure Skill Coding Practices
- Location
SKILL.md:78- Finding
Shell Command Injection Through Documented SQL Invocation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 78, 127, 273, and 307
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable snippets:
bash python ~/.cac/skills/huawei-cloud-doris-sql-check/scripts/doris_sql_tokenizer.py "<sql_text>"bash python ~/.cac/skills/huawei-cloud-doris-sql-check/scripts/doris_sql_parser.py "<sql_text>"bash python ~/.cac/skills/huawei-cloud-doris-sql-check/scripts/doris_sql_checker.py "<sql_text>" allbash python ~/.cac/skills/huawei-cloud-doris-sql-check/scripts/doris_sql_checker.py "<sql_text>" [syntax|spec|all]Technical Analysis
The Skill instructs the agent to insert SQL text directly into double-quoted shell command templates. SQL is intended to be treated only as data, but legitimate SQL can contain double quotes, backticks, dollar signs, command substitutions, semicolons, and other shell metacharacters.
If an agent constructs a command string from these templates and invokes it through a shell, shell parsing and expansion occur before the Python checker receives
sys.argv. Consequently, the tokenizer and parser cannot neutralize the injected syntax.For example, attacker-supplied SQL containing a construct such as:
sql SELECT "$(malicious_command)";can cause
malicious_commandto execute through shell command substitution before the Python process starts. The precise payload and quoting requirements depend on how the invoking agent constructs the final shell command.The Python implementation itself does not spawn subprocesses or evaluate SQL as code. The vulnerability is in the documented invocation workflow rather than in SQL tokenization.
Attack Path
- An attacker supplies SQL for review through a user request, shared artifact, issue, or another input source processed by the agent.
- The SQL contains shell metacharacters or command substitution syntax.
- Following
SKILL.md, the agent replaces<sql_text>with the supp ...[truncated 969 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not interpolate SQL into a shell command string.
- Prefer importing and calling the checker directly:
python from doris_sql_checker import check_sql_markdown report = check_sql_markdown(sql_text, "all") print(report)- If a separate process is required, use a non-shell argument-vector API:
python subprocess.run( [ sys.executable, checker_path, sql_text, "all", ], shell=False, check=True, )- For large or complex SQL, accept the content through standard input or a securely handled input file while still launching the process with an argument list.
- Remove the vulnerable shell templates from
SKILL.mdor replace them with an invocation method that cannot cause shell interpretation. - Explicitly instruct agents and integrators not to use
shell=True, shell command strings, or textual command interpolation for SQL input.
