T09 · Insecure Skill Coding Practices
- Location
convert_commands.py:74- Finding
Arbitrary Python Code Injection in Generated Pytest Modules
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its stated purpose, but it turns command text into runnable tests with unsafe code generation and weak execution safeguards.
Install only for a controlled test environment with trusted txt files and trusted filenames. Review generated pytest files before running them, avoid local shell execution of untrusted commands, and add allowlists or blocking for destructive commands before using this on real hosts or devices.
convert_commands.py:74Arbitrary Python Code Injection in Generated Pytest Modules
The example uses subprocess.run(cmd, shell=True) on a command string that would plausibly originate from txt files being converted into tests. This enables shell injection and arbitrary command execution if any command content is attacker-controlled or insufficiently reviewed, and the surrounding skill context explicitly encourages executing converted commands on local or remote systems.
import subprocess def send_a_cmd(cmd, target): result = subprocess.run(cmd, shell=True, capture_output=True) return result.stdout
Without declared permissions the skill's intent is opaque and cannot be validated.
The trigger matches broad phrases like server testing or NIC testing, which can cause the skill to activate in conversations that are not actually requesting file conversion. In that context, the skill could steer the agent toward generating or handling command-execution-related artifacts without clear user intent, increasing the chance of unsafe or unintended use.
The skill provides examples for SSH and local shell command execution, including directly executing user-supplied commands, but does not warn that these commands may be untrusted and dangerous. Because the skill converts command files into runnable tests, it normalizes arbitrary command execution on hosts or test servers, which materially increases the risk of destructive or unauthorized actions.
The generator turns untrusted text lines directly into executable pytest code that will run commands on host or R5 targets, with only minimal filtering and logging. In this skill's context, the input files are effectively code-like command sources for server environments, so a malicious or mistaken txt entry could trigger destructive operations, service disruption, or unauthorized system changes when the generated tests are executed.
The natural-language interface text is entirely Chinese and does not indicate that users may interact in other languages or that the skill is intentionally limited to a Chinese-speaking environment. This can constitute a language-policy issue when a specific language is implicitly forced without opt-in.
The natural-language docstrings and comments are written in Chinese, which imposes a specific language context for users and maintainers. The file does not indicate that this is a region-specific tool or provide any opt-in or alternative language support.
No suspicious patterns detected.