T09 · Insecure Skill Coding Practices
- Location
SKILL.md:11- Finding
Shell Command Injection Through an Unvalidated City Name
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 11-21
Vulnerability Type: User-controlled shell command construction
Risk Level: HighVulnerable Code
text ## 输入 - 城市名(优先英文,如 Shanghai、Beijing) - 若用户输入中文城市名,可先尝试查询;失败时提示改英文 ## 使用方法 调用 out.in API: curl "out.in/城市名?id=3" 示例: curl "wttr.in/Shanghai?id=3"Technical Analysis
The skill instructs an agent to insert a user-provided city name into a shell command without defining input validation, shell-safe argument handling, or URL encoding. Although the URL is enclosed in double quotes, an attacker can supply a city value containing a double quote followed by shell control characters. If an agent performs direct textual substitution and executes the resulting command through a shell, the attacker can terminate the quoted URL and append an arbitrary command.
The endpoint is also inconsistent: the command template uses
out.in, while the example useswttr.in. Neither command specifies HTTPS explicitly. This inconsistency can cause requests to be sent to an unintended service, while omission of an explicit secure scheme can permit insecure transport depending on client and server behavior.Attack Path
- An attacker submits a crafted city name containing a closing quotation mark, a shell separator, and an operating-system command.
- The agent substitutes that value directly into the documented
curlcommand. - The agent invokes the generated text through a shell.
- The shell interprets the injected separator and executes the appended command independently of
curl. - The injected command runs with the same operating-system privileges, filesystem access, network access, and environment access as the agent process.
For example, a malicious city value shaped like
" ; [attacker-command] ; #would transform the intended URL argument into multiple shell operations if inserted without validation.Impact Assessment
...[truncated 729 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace shell-based URL construction with a structured HTTP client that treats the city name strictly as data.
- If
curlis required, pass the value as a separately encoded parameter, such as withcurl --get --data-urlencode, rather than interpolating it into a command string. - Never invoke the generated request through a shell. Use an argument-array execution interface where the executable and each argument are supplied separately.
- Validate city names against a restrictive policy appropriate to supported locations. Reject quotation marks, shell metacharacters, control characters, URL delimiters, and unexpected input lengths.
- Normalize and URL-encode accepted Unicode city names before constructing the request.
- Correct the endpoint inconsistency and use one explicitly approved HTTPS URL, such as
https://wttr.in/, with redirects and destination hosts restricted where possible. - Run the request operation with minimal filesystem, environment, and network privileges to reduce impact if input handling fails.
- Add tests covering quotation marks, semicolons, command substitutions, newlines, ampersands, pipes, and other shell-sensitive input.
