T09 · Insecure Skill Coding Practices
- Location
SKILL.md:68- Finding
Shell Command Injection Through Unsafe JSON Interpolation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 68-72, 77-81, and 92-96
Vulnerability Type: Shell command injection caused by unsafe interpolation of dynamic data
Risk Level: HighVulnerable Code
bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"参数名": ""}}'bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"参数1": "值1", "参数2": "值2"}}'bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"修改的参数": "新值"}, "filename": "保存的filename"}'Technical Analysis
The Skill instructs an agent to construct JSON request bodies inside single-quoted shell arguments. The parameter names, parameter values, and saved filename are dynamic values derived from API responses or user input.
If the agent implements these templates through direct textual substitution, a value containing a single quote can terminate the shell's quoted argument. The remainder of the value can then be interpreted as shell syntax rather than JSON data. JSON escaping alone is insufficient because shell parsing occurs before
curlreceives the argument.For example, substituting a value shaped like
'; id; #could transform the intended request into multiple shell commands. The originalcurlrequest may fail due to malformed JSON, but the injected command can still execute.The Skill includes free-form inputs such as tire specifications, so the workflow cannot safely assume that all values are numeric. The same weakness applies to initial calculations, incremental modifications, and option-precalculation requests.
Attack Path
- An attacker supplies a crafted transmission parameter value containing a single quote followed b ...[truncated 1355 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not perform textual interpolation of user-controlled or API-derived values inside shell commands.
- Prefer a structured HTTP library such as Python's
urllib.requestor a vetted HTTP client. Construct request bodies as native objects and serialize them withjson.dumps. - If
curlmust be retained, generate the body with a JSON-aware tool and pass it through standard input or a temporary file created with restrictive permissions. For example, usejq --argfor every dynamic string andcurl --data-binary @-. - Pass dynamic values through environment variables or positional arguments rather than embedding them into executable shell source.
- Validate each field according to the API schema:
- Accept only finite numeric values for numeric engineering parameters.
- Restrict option fields to values returned by the API.
- Apply explicit length and character limits to free-form fields such as tire specifications.
- Validate
PRODUCT_IDas an integer. - Treat
filenameas opaque data and never as executable syntax.
- Avoid invoking a shell where it is not necessary. Supplying an argument array directly to a process API prevents shell metacharacters from being interpreted.
- Add tests containing single quotes, command separators, newlines, command substitutions, and malformed JSON to verify that all values remain data rather than executable syntax.
- Run the Skill's network operations under a least-privileged account with restricted filesystem access and narrowly scoped outbound network permissions to reduce impact if request construction is compromised.
