T09 · Insecure Skill Coding Practices
- Location
scripts/capture-window-by-keyword.sh:70- Finding
Overbroad Keyword Matching May Capture an Unintended Window
- Content
View full analysis
len(arr): print(f'Error: index {n} out of range (1-{len(arr)}).', file=sys.stderr) raise SystemExit(2) print(arr[n-1]['id']) else: arr.sort(key=lambda x: 0 if str(x.get('sharing')) == '1' else 1) print(arr[0]['id']) ``` ```bash if ! screencapture -x -l "$WINDOW_ID" "$OUTPUT_PATH"; then echo "Error: screencapture failed for window id $WINDOW_ID." >&2 echo "Check Screen Recording permission for the host process in macOS Settings." >&2 exit 4 fi ``` ### Technical Analysis The script expands application keywords into aliases, including very short values such as `wx` and `tg`. It then applies unrestricted substring matching to a combined string containing the window owner and title. Short aliases can match unrelated words or attacker-controlled window titles. When multiple candidates match and the user does not provide `--index`, the script merely prioritizes windows whose sharing state is `1` and captures the first candidate. It does not require an exact application-owner match, compare bundle identifiers, or request confirmation when matching is ambiguous. The order returned by CoreGraphics and the sharing-state flag do not establish that a window is the target intended by the user. A shareable but unrelated window ca ...[truncated 1519 chars]- Remediation
View remediation
