T09 · Insecure Skill Coding Practices
- Location
scripts/tier1/phase-4-execute-tests.sh:141- Finding
Untrusted tested-Skill content is automatically executed with host and cloud credentials
- Content
View full analysis
Vulnerability Details
File Location:
scripts/tier1/phase-4-execute-tests.sh:141-170, 238-249, 332-375
Related Data-Flow Locations:scripts/tier1/phase-1-skill-analysis.sh:283-326;scripts/tier1/phase-3-gen-testcases.sh:164-205;scripts/tier2/phase-6-full-flow.sh:164-227
Vulnerability Type: Arbitrary command and code execution from untrusted Skill content
Risk Level: HighComplete Code Snippets
Phase 1 extracts executable content from the tested Skill's documentation and classifies writes using a limited keyword heuristic:
python elif cl.startswith('bash ') and 'scripts/' in cl: # 自带脚本(bash scripts/xxx.sh ...)也是可执行命令, 提取为正例 cmd_id += 1 is_write = any(kw in cl.lower() for kw in [ 'create', 'delete', 'update', 'destroy', 'activate', 'reclaim', 'cleanup' ]) commands.append({ 'id': 'CMD-%02d' % cmd_id, 'source': 'SKILL.md-bash-block', 'description': cl[:80], 'command': cl, 'executor': 'script', 'is_write': is_write }) elif cl.startswith('hcloud '): cmd_id += 1 is_write = any(kw in cl.lower() for kw in [ 'create', 'delete', 'update', 'destroy' ]) clean_cmd = re.sub(r'<[^>]+>', '', cl).strip() commands.append({ 'id': 'CMD-%02d' % cmd_id, 'source': 'SKILL.md-bash-block', 'description': clean_cmd[:80], 'command': clean_cmd, 'executor': 'cli', 'is_write': is_write })Phase 3 converts the extracted command into an executable test case:
python functional_cases.append({ 'id': f'TC-F-{tc_f_id:02d}', 'name': cmd.get('description', cmd_text[:60]) if cmd.get('description') else f"命令-{tc_f_id:02d}", 'type': '正向' if not is_write else '变更', 'command': cmd_text, 'expected': 'SDK调用成功并返回数据' if executor == 'sdk' else ('CLI命令执行成功' if executor == 'cli' else '脚本执行成功'), ...[truncated 6074 chars]- Remediation
View remediation
Remediation Suggestions
-
Do not execute documentation-derived shell strings
- Remove all
bash -cexecution of content extracted from a tested Skill. - Parse supported commands into argument arrays.
- Allowlist the exact executable, service, operation, and permitted options.
- Reject shell metacharacters, substitutions, redirections, pipelines, newlines, and additional command separators.
- Remove all
-
Treat every tested Skill as hostile code
- Run packaged scripts and generated SDK snippets only inside a disposable container or virtual machine.
- Use a read-only mount for the tested Skill.
- Do not mount the user's home directory, SSH configuration, cloud configuration, agent state, or unrelated workspace files.
- Apply process, CPU, memory, filesystem, and execution-time limits.
-
Remove credentials from untrusted process environments
- Construct a minimal environment rather than passing
os.environ. - Do not expose long-lived AK/SK values to tested code.
- Use short-lived, narrowly scoped credentials for a disposable test account where live testing is necessary.
- Route approved cloud operations through a trusted broker that validates service, operation, resource scope, region, and request parameters.
- Construct a minimal environment rather than passing
-
Replace heuristic write detection
- Do not infer authorization requirements from keywords such as
createordelete. - Resolve supported operations against structured metadata and classify their effects explicitly.
- Treat unknown or compound commands as unsafe and refuse execution.
- Do not infer authorization requirements from keywords such as
-
Enforce exact per-operation approval
- Present the normalized executable, argument vector, target account, region, resource scope, and credential permissions.
- Bind approval to a hash of the exact command or script.
- Revalidate the hash immediately before execution.
- Require approval for all untrusted scripts and code snippets, not only operations labeled as writes.
-
**Separate static analysis f ...[truncated 544 chars]
-
