T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Unvalidated Database Name Interpolation May Enable Shell Command Injection
- Content
View full analysis
inspector run dbskiter --output-mode=ai --database= inspector report --output report.html dbskiter --output-mode=ai --database= inspector baseline --create dbskiter --output-mode=ai --database= inspector intelligent dbskiter --output-mode=ai --database= inspector anomalies --metric=cpu_usage dbskiter --output-mode=ai --database= inspector root-cause --issue="CPU飙升" ``` Equivalent unquoted database-name placeholders also appear throughout the command examples and decision flows in `SKILL.md`. ### Technical Analysis The Skill instructs an Agent to replace `` with a user-selected database name and execute the resulting command. It does not require validation, shell-safe quoting, or execution through a structured process API. If an Agent constructs a command string and passes it to a shell, metacharacters in the database name can terminate or alter the intended `dbskiter` command. For example, a database name shaped like: ```text prod; attacker-command ``` could produce a command equivalent to: ```bash dbskiter --output-mode=ai --database=prod; attacker-command inspector run ``` The shell would treat the semicolon as a command separator. Exploitability therefore depends on whether the consuming Agent accepts an attacker-controlled database name and executes the generated string through a shell. The document does not establish a safe boundary against that behavior. ### Attack Path 1. An attacker asks the Agent to inspect a database and supplies a database name containing shell metacharacters and an additional command. 2. The Agent substitutes the supplied value for `` as directed by the Skill. 3. The Agent executes the assembled command thr ...[truncated 946 chars]- Remediation
View remediation
` must be validated and supplied as one process argument. 5. If a shell is unavoidable, apply platform-appropriate quoting after validation. Quoting alone should not replace input validation. 6. Add negative tests covering semicolons, pipes, ampersands, redirections, backticks, `$()` substitutions, embedded quotes, spaces, and newline injection. 7. Apply the same structured argument handling to other user-derived parameters, including issue descriptions, metric JSON, anomaly JSON, output paths, and time horizons. ]]>
