T09 · Insecure Skill Coding Practices
- Location
scripts/search.sh:11- Finding
Arbitrary Command Execution via Python Code Injection
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search.sh, line 11
Vulnerability Type: User-controlled input interpolated into executable Python source code
Risk Level: HighVulnerable Code
bash ENCODED=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''$QUERY'''))")Technical Analysis
The
QUERYvariable is controlled by the first command-line argument and is inserted directly into a Python program passed topython3 -c. Although the value is enclosed in triple quotes, an attacker can include a matching'''sequence to terminate the Python string and append arbitrary Python statements.The shell quoting around the
-cargument does not make this safe because variable expansion occurs before Python parses the generated program. Consequently, the query is treated as executable Python syntax rather than strictly as data.For example, a query shaped like the following can terminate the intended string and invoke an operating-system command:
text x''')); __import__('os').system('id'); #The exact payload may be adapted to the target environment. The underlying issue permits arbitrary Python execution and, through modules such as
osorsubprocess, arbitrary local command execution.Attack Path
- The attacker causes the Skill to process a crafted market-search query containing Python syntax.
scripts/search.shassigns that content toQUERY.- Line 11 expands
QUERYinto the source text supplied topython3 -c. - The crafted triple-quote sequence closes the intended Python string.
- Python parses and executes the attacker's appended statements.
- The injected Python can invoke local commands, read accessible files, alter data, or initiate network connections under the identity running the Skill.
Impact Assessment
Successful exploitation provides arbitrary code execution with the privileges of the user or Agent process invoking the s ...[truncated 446 chars]
- Remediation
View remediation
Remediation Suggestions
Pass the query as a separate argument so Python receives it as data rather than generated source code:
bash ENCODED=$(python3 -c 'import sys, urllib.parse; print(urllib.parse.quote(sys.argv[1]))' "$QUERY")Additional hardening measures:
- Retain the quoted
"$QUERY"argument to prevent shell word splitting and pathname expansion. - Consider enforcing a reasonable maximum query length to limit resource abuse.
- Use
curl --fail-with-body --show-error --locationso HTTP failures are handled explicitly. - Add regression tests containing triple quotes, newlines, semicolons, shell metacharacters, and Python expressions, and verify that they are only URL-encoded.
- Run the Skill with least privilege and without unnecessary access to credentials or sensitive local files.
- Retain the quoted
