T09 · Insecure Skill Coding Practices
- Location
SKILL.md:75- Finding
Potential Shell Command Injection Through Unsafe JSON Payload Construction
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:75-78,SKILL.md:88-91, andSKILL.md:135-139
Vulnerability Type: Shell command injection caused by unsafe interpolation into shell and JSON contexts
Risk Level: MediumVulnerable Code
SKILL.md:75-78:bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"有选项的参数名": ""}}'SKILL.md:88-91:bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"参数名1": "值1", "参数名2": "值2", ...}}'SKILL.md:135-139:bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'Technical Analysis
The Skill instructs an Agent to collect parameter names and values and place them into JSON request bodies embedded inside single-quoted shell arguments. It does not require safe JSON serialization, shell escaping, argument-array execution, or validation of the substituted values.
JSON escaping alone is not sufficient when a command is interpreted by a shell. If an implementation performs direct textual substitution, a single quote in an attacker-controlled value can terminate the shell argument. The remaining input can then introduce shell operators and commands. Conversely, manual shell escaping without proper JSON serialization can produce malformed or semantically altered JSON.
The commands are documentation templates rather than directly executable project code, so exploitability depends on how the consuming Agent materializes and executes them. An Agent that constructs a shell command string by replacing the placeholders is vulnerable. An implementation that passes arguments without a shell and serializes the payload using a JSON ...[truncated 1962 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not construct shell command strings by interpolating user-controlled parameter names, values, filenames, product identifiers, or guest codes.
- Prefer a structured HTTP client that accepts native objects and performs JSON serialization automatically. For example, use Python with
requestsorurllib.requestand pass a dictionary to the JSON encoder. - If
curlis required, generate the request body with a trusted JSON serializer and place it in a securely created temporary file. Submit it with--data-binary @fileand remove the file after use. - Invoke subprocesses with an argument array and with shell interpretation disabled. Avoid
shell=True,bash -c,sh -c,eval, and equivalent command-string execution. - Validate product identifiers against the product list returned by the API. Treat filenames and guest codes as opaque server-issued values and reject values outside their documented format before using them in URLs or commands.
- Apply type, length, and range validation to user-entered engineering parameters. Validation should supplement, not replace, context-appropriate serialization.
- Update the Skill instructions to explicitly prohibit direct placeholder substitution into shell commands and provide a safe reference implementation.
- Run the Agent with minimum filesystem and network privileges so that any command-injection defect has limited impact.
