T09 · Insecure Skill Coding Practices
- Location
SKILL.md:116- Finding
Shell Command Injection Through Unescaped Calendar Data
- Content
View full analysis
" add --noprompt --title "" --when "<Start>" --duration <minutes> gcalcli --nocolor --calendar "<Cal>" add --noprompt --allday --title "<Title>" --when "<Date>" ``` ```sh echo 'BEGIN:VCALENDAR VERSION:2.0 BEGIN:VEVENT DTSTART;VALUE=DATE:20260308 SUMMARY:Event Title RRULE:FREQ=YEARLY TRANSP:TRANSPARENT END:VEVENT END:VCALENDAR' | gcalcli import --calendar "<Cal>" ``` ```sh gcalcli --nocolor delete --iamaexpert "<query>" <start> <end> ``` ### Technical Analysis The Skill directs the agent to interpolate calendar names, event titles, dates, search queries, durations, and generated ICS content into shell command strings. It does not require argument-array execution, strict input validation, or shell-safe escaping. Double quotes do not neutralize all shell syntax. If a dynamic value contains a double quote followed by shell operators, it may terminate the intended argument and append another command. The multiline `echo` pattern is also unsafe when generated ICS data contains a single quote, because that character can terminate the shell's single-quoted string. The risk applies to values supplied directly by a user and potentially to text retrieved from calendar events and later reused in commands. Whether exploitation succeeds depends on the execution tool invoking these templates through a shell. If commands are executed as structured argument arrays without shell parsing, the shell-injection path is prevented. The ICS template has an additional data-integrity concern: dynamically generated text fields should be escaped according to RFC 5545, independently of shell escaping. ### Attack Path 1. An attacker supplies an event title, calendar name, or deletion query containing quote-breaking charact ...[truncated 1344 chars]- Remediation
View remediation
