T09 · Insecure Skill Coding Practices
- Location
scripts/tikhub.py:303- Finding
Shell Command Injection in Background Whisper Transcription
- Content
View full analysis
{log_file} 2>&1 &" subprocess.run(nohup_cmd, shell=True) return output_path ``` ### Technical Analysis The function constructs a shell command by joining command arguments into a single string and executes it with `shell=True`. Values including `audio_path`, `model`, `language`, `output_dir`, and `log_file` are not shell-escaped. Because the shell interprets metacharacters such as semicolons, command substitutions, pipes, redirections, and ampersands, a crafted argument can terminate the intended Whisper command and introduce an additional operating-system command. Although some normal call paths derive the audio path from a downloaded video, `whisper_transcribe` is also publicly exported by `scripts/__init__.py`. Callers can therefore pass malicious values directly. The CPU pipeline also reaches this vulnerable background mode. ### Attack Path 1. An attacker influences a value passed to `whisper_transcribe`, such as `model`, `language`, or `audio_path`. 2. The attacker includes shell syntax in that value, for example a semicolon followed by another command. 3. The value is inserted verbatim into `nohup_cmd`. 4. `subprocess.run(..., shell=True)` passes the assembled string to the system shell. 5. The shell executes both the intended Whisper operation and the injected command. ### Impact Assessment Successful exploitation allows arbitrary command execution with the privileges of the user running the Skill. The injected process could: - Read or modify files ac ...[truncated 374 chars]- Remediation
View remediation
