T09 · Insecure Skill Coding Practices
- Location
modules/recorder.sh:171- Finding
Arbitrary Python Code Execution Through Unvalidated Numeric Arguments
- Content
View full analysis
"$weight_history" fi python3 << EOF import json with open("$weight_history", 'r', encoding='utf-8') as f: history = json.load(f) # Remove an existing record from the same day history = [h for h in history if h['date'] != '$today'] history.append({'date': '$today', 'weight': $weight}) with open("$weight_history", 'w', encoding='utf-8') as f: json.dump(history, f, ensure_ascii=False, indent=2) EOF ``` ### Technical Analysis The `record_steps` and `record_weight` functions accept command-line arguments without validating their format. These values are expanded directly into unquoted Python heredocs and consequently become part of executable Python source code. For example, `$steps` is not passed to Python as a string or integer argument. Instead, it is substituted into this statement: ```python data['steps'] = ATTACKER_CONTROLLED_TEXT ``` An attacker can provide text containing a valid initial expression, a semicolon, additional Python statements, and a comment marker. Python then interprets the supplied statements as program code rather than record data. Quoting the argument when invoking the Bash scrip ...[truncated 1458 chars]- Remediation
View remediation
&2 return 1 } ``` - Validate weight as a decimal number and enforce medically reasonable minimum and maximum values. - Pass values as command-line arguments or environment variables instead of inserting them into Python source. - Use a quoted heredoc delimiter to disable shell interpolation: ```bash python3 - "$daily_file" "$steps" <<'PY' import json import sys path = sys.argv[1] try: steps = int(sys.argv[2]) except ValueError: raise SystemExit("Invalid step count") with open(path, "r", encoding="utf-8") as f: data = json.load(f) data["steps"] = steps with open(path, "w", encoding="utf-8") as f: json.dump(data, f, ensure_ascii=False, indent=2) PY ``` - Apply the same typed-argument pattern to both weight-update heredocs. - Return an error before modifying files if validation fails. ]]>
