T09 · Insecure Skill Coding Practices
- Location
scripts/moltbook.sh:93- Finding
Unescaped CLI Input Allows JSON Request-Body Injection
- Content
View full analysis
Vulnerability Details
File Location:
scripts/moltbook.sh:93-113(vulnerable request construction at lines 101 and 113)
Vulnerability Type: JSON injection through unsafe string interpolation
Risk Level: Mediumbash reply) post_id="$2" content="$3" if [[ -z "$post_id" || -z "$content" ]]; then echo "Usage: moltbook reply POST_ID CONTENT" exit 1 fi echo "Posting reply..." api_call POST "/posts/${post_id}/comments" "{\"content\":\"${content}\"}" ;; create) title="$2" content="$3" submolt="${4:-29beb7ee-ca7d-4290-9c2f-09926264866f}" if [[ -z "$title" || -z "$content" ]]; then echo "Usage: moltbook create TITLE CONTENT [SUBMOLT_ID]" exit 1 fi echo "Creating post..." api_call POST "/posts" "{\"title\":\"${title}\",\"content\":\"${content}\",\"submolt_id\":\"${submolt}\"}" ;;Technical Analysis
The
title,content, andsubmoltvalues originate from command-line arguments and are interpolated directly into JSON strings. The implementation does not encode quotation marks, backslashes, control characters, or other JSON metacharacters.Although the quoted shell expansions do not directly create shell-command injection, crafted input can terminate the intended JSON string and introduce additional properties. For example, reply content resembling
text","extra":"valueproduces a body with an attacker-suppliedextraproperty. Inputs containing unescaped quotation marks or newlines can also make the body invalid and prevent the authenticated operation from completing.The precise effect of injected fields depends on which properties the Moltbook API accepts or ignores. The demonstrated flaw is therefore authenticated request-body manipulation and malformed-request denial of operation, rather than arbitrary ...[truncated 1170 chars]
- Remediation
View remediation
Remediation Suggestions
Construct request bodies with a real JSON serializer instead of string interpolation. For example, when
jqis available:bash reply_data=$(jq -n --arg content "$content" '{content: $content}') api_call POST "/posts/${post_id}/comments" "$reply_data" create_data=$(jq -n \ --arg title "$title" \ --arg content "$content" \ --arg submolt_id "$submolt" \ '{title: $title, content: $content, submolt_id: $submolt_id}') api_call POST "/posts" "$create_data"If zero external dependencies are required, use a standard JSON implementation such as Python's
jsonmodule as a fallback. Do not implement JSON escaping with regular expressions.Additionally:
- Validate
post_idandsubmoltagainst the expected UUID syntax before including them in URLs or bodies. - Apply reasonable length limits to titles and content.
- Reject control characters when they are not required.
- Add tests covering quotation marks, backslashes, newlines, Unicode, and attempted property injection.
- Make API requests fail on HTTP errors and distinguish transport errors from valid JSON responses.
- Validate
