T09 · Insecure Skill Coding Practices
- Location
scripts/play.sh:30- Finding
Command Injection Through Unvalidated Duration Input
- Content
View full analysis
- Remediation
View remediation
&2 exit 2 fi if (( DURATION > 86400 )); then printf 'Error: duration exceeds the permitted maximum\n' >&2 exit 2 fi ``` Additional hardening should include: 1. Reject a duration option when its value is missing: ```bash -d|--duration) [[ $# -ge 2 ]] || { printf 'Error: missing duration value\n' >&2 exit 2 } DURATION=$2 shift 2 ;; ``` 2. Apply similar strict numeric validation to `VOLUME` before inserting it into the `ffplay` filter. 3. Set documented minimum and maximum values to prevent excessive playback duration or resource use. 4. Use `printf` rather than `echo` for predictable error handling. 5. Add regression tests with malformed arithmetic expressions, command substitutions, negative values, empty values, and extremely large integers. ]]>
