T09 · Insecure Skill Coding Practices
- Location
SKILL.md:151- Finding
Command and JavaScript Injection Through Unsafe Parameter Interpolation
- Content
View full analysis
ALIBABA_CLOUD_ACCESS_KEY_SECRET= auto-static-web deploy -d --bucket --domain --region --yes --https ``` ```bash node -e " const fs = require('fs'); const path = require('path'); const authPath = path.join(require('os').homedir(), '.ossify', 'auth.json'); const auth = JSON.parse(fs.readFileSync(authPath, 'utf8')); auth.lastDeploy = { bucket: 'BUCKET', domain: 'DOMAIN', region: 'REGION', https: true, dist: 'DIST' }; fs.writeFileSync(authPath, JSON.stringify(auth, null, 2)); " ``` ### Technical Analysis The Skill instructs the agent to substitute credentials and user-provided deployment parameters directly into shell command text and JavaScript string literals. No robust shell escaping, JavaScript escaping, or argument-array execution mechanism is specified. The deployment directory, bucket name, and domain are collected from the user. If a malicious value contains shell metacharacters, command substitutions, quotes, or JavaScript syntax, it may escape its intended argument or string context. For example, an unquoted deployment directory containing command substitution syntax could be evaluated by the shell. A single quote in a value embedded in the `node -e` snippets could terminate the JavaScript literal and introduce additional JavaScript statements. The credential format checks reduce the available character set for credentials, but equivalent validation and safe argument handling ...[truncated 1175 chars]- Remediation
View remediation
