T09 · Insecure Skill Coding Practices
- Location
SKILL.md:478- Finding
Command injection through unquoted WAF event data in generated remediation commands
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:478-485;references/rule-recommendation-guide.md:105-123, 162-175
Vulnerability Type: Command injection through unsafe command generation
Risk Level: HighVulnerable Code
From
SKILL.md:478-485:bash hcloud WAF CreateCustomRule --policy_id={policy_id} \ --name={rule_name} \ --action.category=block \ --conditions.1.category={field_category} \ --conditions.1.logic_operation={logic_op} \ --conditions.1.contents.1={match_value} \ --priority=50 \ --time=falseFrom
references/rule-recommendation-guide.md:105-123:bash hcloud WAF CreateCustomRule \ --policy_id={policy_id} \ --name={rule_name} \ --action.category=block \ --conditions.1.category=url \ --conditions.1.logic_operation=contain \ --conditions.1.contents.1={targeted_url} \ --conditions.2.category=params \ --conditions.2.logic_operation=contain \ --conditions.2.contents.1={sqli_pattern} \ --priority=30 \ --time=falseFrom
references/rule-recommendation-guide.md:162-175:bash hcloud WAF CreateCustomRule \ --policy_id={policy_id} \ --name={rule_name} \ --action.category=block \ --conditions.1.category=user-agent \ --conditions.1.logic_operation=contain \ --conditions.1.contents.1={scanner_signature} \ --priority=31 \ --time=falseTechnical Analysis
The Skill analyzes WAF records whose URL, payload, parameters, and User-Agent values originate from requests made by remote web clients. It then instructs the Agent to generate copy-paste-ready
hcloudcommands using values such as{targeted_url},{sqli_pattern},{scanner_signature}, and{match_value}.These values are placed directly into shell command arguments without quoting, escaping, strict validation, or structured serialization. A remote requester can therefore place PowerShell metacharacters or statement separators in a logged request field. If that value is reproduced in a recommendation, ...[truncated 2243 chars]
- Remediation
View remediation
Remediation Suggestions
- Never interpolate WAF event fields directly into shell command strings.
- Treat URLs, request parameters, payloads, headers, User-Agent values, hostnames, descriptions, and generated rule names as untrusted.
- Generate a structured API request object and serialize it with
ConvertTo-Jsoninstead of constructing command text. - Use
--cli-jsonInputfor attacker-influenced rule values. Write the JSON through a secure, uniquely named file and pass only the trusted file path tohcloud. - Where direct invocation is unavoidable, use PowerShell argument arrays and native process APIs rather than a command string interpreted by PowerShell.
- Apply strict allowlists to fields with narrow formats:
- Validate policy and project identifiers against their documented identifier syntax.
- Validate IP addresses and CIDR values with dedicated parsers.
- Restrict country codes to two ASCII letters.
- Generate rule names locally instead of deriving them from request content.
- Reject control characters and shell metacharacters as defense in depth, but do not rely on filtering as a replacement for structured argument passing.
- Display all event-derived values separately from executable commands and clearly mark them as untrusted.
- Add tests containing PowerShell separators, quotes, substitutions, and newline characters to verify that every value remains a single inert API field.
- Apply the same remediation to all corresponding templates in
references/rule-recommendation-guide.md, not only the primary template inSKILL.md.
