T09 · Insecure Skill Coding Practices
- Location
SKILL.md:108- Finding
Shell Command Injection Through Unsafely Interpolated Calendar Values
- Content
View full analysis
" today +180d` - Custom: `gcalcli --nocolor search "" ` ``` ```text - Timed event: - `gcalcli --nocolor --calendar "" add --noprompt --title "" --when "<Start>" --duration <minutes>` - All-day event: - `gcalcli --nocolor --calendar "<Cal>" add --noprompt --allday --title "<Title>" --when "<Date>"` ``` ```sh echo 'BEGIN:VCALENDAR VERSION:2.0 BEGIN:VEVENT DTSTART;VALUE=DATE:20260308 SUMMARY:Event Title RRULE:FREQ=YEARLY TRANSP:TRANSPARENT END:VEVENT END:VCALENDAR' | gcalcli import --calendar "<Cal>" ``` ```text - Delete (non-interactive, bounded): - `gcalcli --nocolor delete --iamaexpert "<query>" <start> <end>` ``` ### Technical Analysis The documented command templates interpolate calendar names, event titles, search terms, dates, and other potentially user-controlled values directly into shell command text. Surrounding values with double quotes does not make a dynamically constructed shell command safe: shell metacharacters such as command substitutions can become executable syntax when the completed command string is parsed by a shell. The ICS import example is additionally built using a single-quoted `echo` payload. An apostrophe introduced into an event title or another ICS field can terminate the quoted string and permit additional shell syntax. The Skill does not require use of a shell-free argument-array API, robust shell escaping, or validation of control characters. Calendar data can also originate from shared or externally controlled calendars. Reusing an attacker-controlled event value in a later generated command can therefore create a stored injection path, depending on how the hosting agent constructs and executes commands. ### Attack Path 1. An attacker supplie ...[truncated 1272 chars]- Remediation
View remediation
