T09 · Insecure Skill Coding Practices
- Location
SKILL.md:82- Finding
Shell Command Injection Through an Unescaped Image Prompt
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 82-95
Vulnerability Type: Shell command injection through unsafe interpolation of user-controlled input
Risk Level: HighVulnerable Code
bash curl https://apis.juhe.cn/a2a/query \ -d '{"resourceId":"824","data":{"prompt":"<用户描述的图像内容>","size":<用户描述的尺寸>}}' \ -H "Content-Type: application/json"Technical Analysis
The Skill directs the Agent to substitute a user-controlled image prompt into a single-quoted shell argument and then execute the resulting
curlcommand. Although the document mentions escaping quotation marks for JSON, JSON escaping does not make data safe for interpolation into a shell command.A single quote in the prompt can terminate the shell argument. Subsequent prompt content can then be interpreted by the shell as operators, commands, redirections, or substitutions rather than as JSON data. Escaping only JSON double quotes is therefore insufficient.
The size value is also inserted without JSON string delimiters. The documented validation limits it to values from 1 through 5, but this protection depends entirely on the Agent consistently enforcing the natural-language instruction.
Attack Path
- An attacker requests image generation and accepts the paid-service terms.
- The attacker supplies a prompt containing a single quote followed by shell syntax and an additional command.
- The Agent directly replaces the prompt placeholder in the documented
curltemplate. - The shell parses the injected quote as the end of the original
-dargument. - The attacker-controlled shell syntax executes with the privileges of the Agent process.
- The injected command can access files, environment variables, credentials, network resources, or other capabilities available to that process.
Exploitation requires the Agent to implement the documented request by textual substitution into a shell command. ...[truncated 759 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not build shell commands by inserting user-controlled text into command templates.
- Use a structured HTTP library that accepts an object and performs JSON serialization without invoking a shell.
- If a command-line client is unavoidable, construct the request body with a trusted JSON serializer such as
jq, pass values as discrete arguments, and avoidsh -c,eval, or equivalent shell evaluation. - Treat JSON escaping and shell escaping as separate security boundaries. JSON quote handling alone must not be presented as sufficient.
- Enforce the prompt length limit programmatically and validate
sizeusing a strict allowlist of integer values1through5. - Add security tests using prompts containing single quotes, double quotes, backticks, command substitutions, newlines, redirection operators, and shell separators.
- Run the Agent with least privilege and restrict its filesystem and network access to reduce the impact of any future command-injection defect.
