T09 · Insecure Skill Coding Practices
- Location
SKILL.md:63- Finding
Shell Command Injection Through Unsafe JSON Interpolation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 63–67, 75–78, 90–93, and 99–102
Vulnerability Type: Shell command injection caused by unsafe interpolation of untrusted values
Risk Level: HighVulnerable Code
Lines 63–67:
bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"参数名": ""}}'Lines 75–78:
bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"参数1": "值1", "参数2": "值2"}}'Lines 90–93:
bash curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \ -H "Content-Type: application/json" \ -d '{"inputs": {"修改的参数": "新值"}, "filename": "保存的filename"}'Lines 99–102:
bash curl -s -X POST "https://jixietools.com/api/v1/production_sheets/guest_create" \ -H "Content-Type: application/json" \ -d '{"product_id": PRODUCT_ID, "ref": "保存的filename"}'Technical Analysis
The skill instructs an agent to construct shell commands by replacing placeholders with parameter names, user-provided values, product identifiers, and an API-provided filename. These values are placed directly inside single-quoted JSON passed to
curl -d.The instructions do not require JSON serialization, shell-safe argument construction, identifier validation, or rejection of shell metacharacters. If an agent performs literal textual substitution, a value containing a single quote can terminate the shell string. Subsequent shell syntax can then be interpreted as a local command rather than as JSON data.
Both user input and remote API responses must be treated as untrusted. In particular, the incremental-calculation and production-sheet commands reuse a remotely supplied
filename, creating an additional injection path if the external service or its response is comprom ...[truncated 1725 chars]- Remediation
View remediation
Remediation Suggestions
- Replace shell command templates with a typed HTTP client that accepts URL, headers, and JSON objects as separate structured values.
- Serialize request bodies with a standard JSON library rather than manually embedding values into quoted shell strings.
- If shell-based examples must be retained, construct payloads with
jq --argorjq --argjson, write the result to a safely created temporary file, and submit it usingcurl --data-binary @file. - Pass shell arguments as an argument array without invoking
sh -c,bash -c,eval, or equivalent string-evaluation mechanisms. - Validate
PRODUCT_IDas an integer before placing it in a URL or JSON document. - Validate API-provided filenames and references against a strict allowlist appropriate to the documented server format. Do not interpret them as paths or shell syntax.
- Treat all user values and remote responses as untrusted, including parameter names, option values, filenames, guest codes, and returned URLs.
- Run the skill with least privilege, a restricted filesystem view, minimal environment variables, and network access limited to the required API host.
- Add adversarial tests covering quotes, backslashes, newlines, command substitutions, shell separators, and malformed JSON.
