T09 · Insecure Skill Coding Practices
- Location
SKILL.md:89- Finding
Shell Command Injection in Initial Calculation Request
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 89–92
Vulnerability Type: Shell command injection through unsafe JSON construction
Risk Level: HighVulnerable Code
bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"参数名1": "值1", "参数名2": "值2", ...}}'Technical Analysis
The Skill directs the agent to collect parameter values from the user and insert them into JSON enclosed in a single-quoted shell argument. It does not require JSON serialization, shell escaping, input validation, or use of a shell-free HTTP client.
A user-provided value containing a single quote can terminate the
-dargument. Subsequent shell metacharacters can then be interpreted as commands rather than request data. For example, a value following the schematic form'; id; #could close the quoted argument, run a local command, and comment out the remainder.Exploitation depends on an implementing agent substituting values directly into this documented shell template, but that is precisely the workflow the Skill prescribes.
Attack Path
- The Skill asks the user for a product parameter.
- The attacker supplies a value containing a single quote followed by shell syntax.
- The agent directly substitutes that value into the documented
curl -d '...'command. - The single quote terminates the intended JSON shell argument.
- The shell parses the remaining attacker-controlled text as one or more local commands.
- Those commands execute with the operating-system privileges of the agent process.
Impact Assessment
Successful exploitation permits arbitrary command execution within the agent's local security context. The attacker could read files accessible to the agent, alter project or user files, access environment variables, invoke installed tools, make additional network requests, or establish further com ...[truncated 286 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not interpolate parameter names or values into shell command strings.
- Prefer an HTTP library that accepts a structured object and serializes it through a JSON API, such as Python
requests.post(url, json=payload). - If
curlis required, construct the request body with a JSON serializer such asjq -n --arg, save it to a securely created file, and submit it using--data-binary @file. - Pass commands as argument arrays without invoking a shell.
- Validate each value against the parameter schema returned by the service, including expected type, range, length, and enumerated options.
- Treat validation as defense in depth; do not rely on character filtering as a replacement for safe serialization and shell avoidance.
