T09 · Insecure Skill Coding Practices
- Location
scripts/search.sh:5- Finding
Arbitrary Command Execution Through Bash Arithmetic Injection
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search.sh, lines 5–24
Vulnerability Type: Shell command injection through unsafe arithmetic evaluation
Risk Level: HighVulnerable Code
bash CURSOR="${2:-0}" if [ -z "$QUERY" ]; then echo "Usage: $0 \"query\" [cursor]" >&2 exit 1 fi if [ -z "${BRIGHTDATA_API_KEY:-}" ]; then echo "Error: BRIGHTDATA_API_KEY is not set." >&2 echo "Get a key from https://brightdata.com/cp" >&2 exit 1 fi if [ -z "${BRIGHTDATA_UNLOCKER_ZONE:-}" ]; then echo "Error: BRIGHTDATA_UNLOCKER_ZONE is not set." >&2 echo "Create a zone at brightdata.com/cp" >&2 exit 1 fi # Build Google search URL with pagination START=$((CURSOR * 10))Technical Analysis
The script copies its attacker-controllable second command-line argument directly into
CURSORand subsequently evaluates that value inside a Bash arithmetic expansion:bash START=$((CURSOR * 10))Bash arithmetic contexts evaluate expressions rather than treating variable values strictly as decimal integers. Crafted expressions can use features such as array subscripts, where command substitutions may be evaluated by the shell. Because the script does not first enforce a decimal-integer format, a malicious cursor can cause local commands to execute while the arithmetic expression is being resolved.
Quoting the original assignment does not mitigate this issue because the dangerous interpretation occurs later, within the arithmetic context.
Attack Path
- An attacker obtains control over, or influences, the pagination argument supplied to
scripts/search.sh. - The script assigns that argument verbatim to
CURSOR. - The script evaluates
CURSORas part of a Bash arithmetic expression at line 24. - A crafted array-subscript expression triggers command substitution during arithmetic evaluation.
- The inject ...[truncated 1289 chars]
- An attacker obtains control over, or influences, the pagination argument supplied to
- Remediation
View remediation
Remediation Suggestions
Validate the cursor as a bounded, non-negative decimal integer before using it in any arithmetic context:
bash CURSOR="${2:-0}" if [[ ! "$CURSOR" =~ ^[0-9]+$ ]]; then echo "Error: cursor must be a non-negative decimal integer." >&2 exit 1 fi if (( 10#$CURSOR > 1000 )); then echo "Error: cursor must not exceed 1000." >&2 exit 1 fi START=$((10#$CURSOR * 10))The
10#prefix explicitly forces base-10 interpretation and avoids unexpected octal handling for values with leading zeroes. The upper bound should be adjusted to the largest pagination value legitimately required by the service.Additional hardening should include:
- Treating every command-line argument as untrusted, including arguments generated by an agent.
- Enabling strict shell behavior where compatible, such as
set -euo pipefail. - Running the Skill under a minimally privileged account.
- Supplying only the environment variables required for the operation.
- Adding regression tests that reject arithmetic expressions, command substitutions, signs, whitespace, and non-decimal input.
