T09 · Insecure Skill Coding Practices
- Location
scripts/run_claude.py:61- Finding
Shell Command Injection Through the Prompt and Working Directory
- Content
View full analysis
&1' ] ``` ### Technical Analysis The `prompt` and `temp_workdir` values are interpolated directly into a command string passed to `su -c`. Although `subprocess.Popen` later receives an argument list, the command supplied after `su -c` is explicitly interpreted by a shell. Double quotes around `prompt` do not prevent shell injection. A prompt containing a double quote followed by shell control operators can terminate the intended argument and append a new command. For example, a value shaped like `" ; attacker_command ; #` would cause the shell to execute `attacker_command`. The working directory is similarly unsafe because `temp_workdir` is inserted after `cd` without shell quoting. Its final component is derived from the basename of the caller-supplied `workdir`, so a directory name containing shell metacharacters may alter the command. ### Attack Path 1. An attacker gains control over, or influences, the `prompt` argument passed through the CLI or Python API. Alternatively, the attacker supplies a project directory whose basename contains shell metacharacters. 2. The runner embeds the controlled value into the `su -c` command string without safe quoting. 3. The shell launched by `su` parses the injected quotation marks and command separators. 4. The injected command executes under the selected target account. 5. The attacker can read or modify any resources accessible to that account and can potentially manipulate the temporary project so that privileged synchronization performs additional unsafe operations. ### Impact Assessment Successful exploitation provides arbitrary command execution with the privileges of the acc ...[truncated 530 chars]- Remediation
View remediation
