T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Shell Command Injection Through User-Controlled Text
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10-11
Vulnerability Type: OS command injection caused by unsafe shell command construction
Risk Level: HighVulnerable Code
The following is an English rendering of the complete vulnerable instruction:
text 2. Use the built-in command-line tool (for example, `bash` or `exec`) to run the Python script in the current directory (`{baseDir}`). 3. Command example: `python {baseDir}/tool.py "<extracted text>"`Technical Analysis
The skill directs the agent to extract attacker-controlled text and interpolate it into a command that may be executed through
bashor another shell. Enclosing input in double quotes does not make shell interpolation safe. Shell constructs such as command substitution with$()remain active inside double quotes. An attacker can also inject a closing quote followed by shell control operators.For example, if the extracted text is
$(id), the generated command may resemble:bash python /skill/tool.py "$(id)"The shell executes
idbefore launching Python. A quote-breaking payload such as"; id; #can terminate the argument and execute a separate command.tool.pyitself only converts its first argument to uppercase and does not invoke a shell. The vulnerability originates in the documented invocation procedure, before the Python script receives the argument.Attack Path
- An attacker invokes the skill and supplies text containing shell syntax, such as
$(id)or"; id; #. - The agent treats the malicious value as the core text to transform.
- Following
SKILL.md, the agent inserts that value into the documented command string. - The command is submitted to
bash,exec, or another shell-capable execution tool. - The shell evaluates the injected substitution or control operators before or alongside
tool.py. - The injected operating-system command executes with the sa ...[truncated 603 chars]
- An attacker invokes the skill and supplies text containing shell syntax, such as
- Remediation
View remediation
Remediation Suggestions
-
Do not construct a shell command by concatenating or interpolating user-controlled text.
-
Invoke Python through a process API that accepts an argument array and does not start a shell. Conceptually, use arguments equivalent to:
text executable: python arguments: [{baseDir}/tool.py, user_input] shell: false -
Alternatively, pass the text through standard input and modify
tool.pyto read fromsys.stdin. -
Explicitly prohibit
bash -c,sh -c,shell=True, and command-string interpolation in the skill instructions. -
If the execution environment only supports shell command strings, avoid passing untrusted text through that interface. Shell escaping is error-prone and should not be the primary defense.
-
Run the skill with least privilege and restrict its filesystem, environment-variable, credential, and network access to reduce impact if an execution boundary is bypassed.
-
Add regression tests using payloads such as
$(id), backticks, quotes, semicolons, newlines, and shell control operators, verifying that each value reachestool.pyonly as literal text.
-
