T09 · Insecure Skill Coding Practices
- Location
SKILL.md:91- Finding
Shell Command Injection Through Initial Calculation Parameters
- Content
View full analysis
/tmp/agent_identity ; # ``` could transform the intended `curl` invocation into a sequence that executes `id` locally and comments out the remainder of the generated command. Parameter names obtained from the remote API may create the same problem if they are interpolated without serialization. JSON escaping alone is insufficient if JSON is subsequently embedded in a shell command; both JSON and shell parsing boundaries must be handled safely. The flagged uses of `curl | python3 -m json.tool` do not execute downloaded code. They pass API responses to Python's JSON formatter and therefore do not constitute remote payload retrieval and execution. The confirmed issue is the unsafe construction of request commands. ### Attack Path 1. The Skill requests an input parameter from the user. 2. An attacker supplies a value containing a single quote followed by shell metacharacters and a command. 3. The Agent substitutes that value into the documented `curl -d '...'` template. 4. The injected quote terminates the JSON shell argument. 5. The local shell interprets the attacker's remaining ...[truncated 760 chars]- Remediation
View remediation
