T09 · Insecure Skill Coding Practices
- Location
SKILL.md:23- Finding
Shell Command Injection Through a User-Controlled Identifier
- Content
View full analysis
" ``` ``` ### Technical Analysis The skill permits a user to provide an unrestricted custom identifier and instructs the agent to interpolate that value into a shell command. The identifier is placed between double quotes, but double quoting is not sufficient if the interpolated value itself contains a double quote, command substitution, backticks, or syntax that terminates the quoted argument. For example, a manual identifier resembling the following can escape the intended argument: ```text "; attacker_command; # ``` If substituted verbatim, the generated command becomes structurally equivalent to: ```bash node ~/.openclaw/workspace/skills/openclaw-buddy/scripts/buddy.js ""; attacker_command; #" ``` The shell would run `attacker_command` separately from the Node.js process. The JavaScript implementation reads `process.argv[2]` and does not itself evaluate the identifier. The vulnerability arises before Node.js starts, at the documented shell-command construction boundary. Exploitability therefore depends on the agent or runtime following the documented command through a shell and inserting the user-controlled value verbatim. ### Attack Path 1. An attacker invokes the skill and supplies a custom buddy identifier. 2. The custom identifier includes a closing quote followed by shell ...[truncated 1159 chars]- Remediation
View remediation
