T09 · Insecure Skill Coding Practices
- Location
SKILL.md:79- Finding
Unsafe Shell Command Construction Allows Command Injection
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 79–81, 91–93, 131–133, and 144–146
Vulnerability Type: Shell command injection through unsafe interpolation into JSON and command-line arguments
Risk Level: MediumVulnerable Code
Lines 79–81:
bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"有选项的参数名": ""}}'Lines 91–93:
bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"参数名1": "值1", "参数名2": "值2", ...}}'Lines 131–133:
bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'Lines 144–146:
bash curl -s -X POST "https://jixietools.com/api/v1/production_sheets/guest_create" \ -H "Content-Type: application/json" \ -d '{"product_id": PRODUCT_ID, "ref": "保存的filename"}'Technical Analysis
The Skill instructs an agent to construct shell commands by inserting parameter names, parameter values, product identifiers, and API-returned filenames directly into quoted command strings. Several of these values originate from users or from an external API and must therefore be considered untrusted.
The JSON body is enclosed in a shell single-quoted argument. If an inserted value contains a single quote, it can terminate that argument. Shell metacharacters following the quote may then be interpreted as additional commands. JSON escaping alone is insufficient because shell parsing occurs before
curlreceives the request.The vulnerability becomes exploitable when an agent follows these templates through textual interpolation and executes the resulting command using a shell. The Markdown file does not itself execute commands, but its ...[truncated 2012 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace shell command templates with a structured HTTP client that accepts the URL, headers, and JSON body as separate typed values.
- Serialize request bodies using a standard JSON library rather than manually concatenating JSON strings.
- If
curlmust be used, generate the request body with a JSON serializer and invokecurlwithout a shell, passing each argument separately through a process API. - Never interpolate user-controlled or API-controlled values into command text, including parameter names, parameter values, product IDs, filenames, and guest codes.
- Validate
PRODUCT_IDas an integer and constrain API-returned identifiers such asfilenameandguest_codeto documented character sets and maximum lengths. - Treat all remote API fields as untrusted, even when returned by the expected HTTPS origin.
- Run network operations in a restricted environment with minimal filesystem access, no unnecessary credentials, and no elevated privileges.
- Add tests containing quotes, backslashes, newlines, command separators, and shell substitution syntax to verify that inputs remain data and cannot alter command structure.
