T09 · Insecure Skill Coding Practices
- Location
SKILL.md:58- Finding
Command Injection Through Shell-Interpolated Video URLs
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 58-78
Vulnerability Type: Shell command injection through untrusted URL interpolation
Risk Level: HighVulnerable Code
bash # Use dokobot to read the page with automatic JavaScript rendering dokobot read "<url>" --local --timeout 5000The Skill also instructs substitution of a supplied Douyin short link into this command sequence:
bash # Douyin short link → complete URL FULL_URL=$(curl -sL "https://v.douyin.com/xxx" -w "%{url_effective}" -o /dev/null) # Then pass it to dokobot dokobot read "$FULL_URL" --local --timeout 5000Technical Analysis
The Skill accepts a video URL controlled by the user and instructs the Agent to place that value into Bash command text. Enclosing the URL in double quotes does not make shell interpolation safe. Bash still evaluates command substitutions such as
$(command)and backtick expressions inside double-quoted strings. A quotation mark in a value copied directly into the command can also terminate the intended argument and introduce additional shell syntax.The documented platform check only looks for strings such as
douyin.com,v.douyin.com,bilibili.com, orb23.tv. It does not require structured URL parsing, an exact hostname match, a fixed HTTPS scheme, or rejection of shell metacharacters. Consequently, a crafted value may appear to reference an accepted platform while carrying shell syntax.The short-link workflow introduces an additional trust boundary. It follows redirects with
curl -Land passes the resulting URL to another command without requiring validation of the final scheme and hostname. Although quoting the expandedFULL_URLprevents ordinary shell syntax contained in the variable from being re-evaluated, the original user value remains dangerous if the Agent substitutes it directly into thecurlcommand template. Redirect validation is also necessary to prevent retrieval from unintended destinat ...[truncated 1589 chars]- Remediation
View remediation
Remediation Suggestions
-
Do not construct shell commands by inserting user-controlled URLs into command text. Invoke the required program through an API that accepts an argument array without passing through a shell.
-
If Bash cannot be avoided, pass the URL as a positional parameter rather than embedding it in the script:
bash bash -c 'exec dokobot read "$1" --local --timeout 5000' -- "$VALIDATED_URL"The tool interface must bind
VALIDATED_URLas a separate argument; the Agent must not generate the outer command by textual concatenation.-
Validate URLs with a structured URL parser before invoking any network utility:
- Permit only the
httpsscheme. - Require an exact hostname from an explicit allowlist.
- Reject usernames, passwords, malformed ports, control characters, and ambiguous encodings.
- Do not use substring matching to validate hosts.
- Normalize the hostname before comparison.
- Permit only the
-
Validate redirects independently. For short links, inspect every redirect target or at least the final effective URL and reject destinations outside the explicitly approved Douyin or Bilibili host allowlist. Consider limiting the number of redirects.
-
Reject shell metacharacters as defense in depth, including command-substitution syntax, backticks, unescaped quotation marks, newlines, and null bytes. This must supplement, not replace, shell-free process invocation.
-
Reduce tool permissions to the minimum necessary. Remove unused
Bash(node *),Bash(mkdir *), andBash(rm *)permissions. Prefer narrowly scoped network and Feishu APIs over general Bash execution. -
Align the allowed-tool declaration with the documented workflow. Explicitly define narrowly constrained access for required tools instead of relying on broad shell permissions or documenting commands that are absent from the allowlist.
-
