T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
Shell Command Injection Through User-Controlled Article URL
- Content
View full analysis
]*>(.*?)', html, re.DOTALL) body = re.sub(r'<[^>]+>', '', m.group(1)).strip() if m else '' print(f'TITLE:{title}') print(f'NAME:{name}') print(f'BODY:{body}') " ``` ### Technical Analysis The Skill permits use of the `exec` tool and directs the Agent to replace the `"链接"` placeholder with a URL supplied by the user. The URL is embedded in shell command text rather than passed through a shell-free argument-array interface. Surrounding the placeholder with double quotes is not sufficient sanitization. If substitution is performed literally, an input containing a double quote followed by shell syntax can terminate the quoted argument and introduce additional shell commands. Command substitution and other shell expansion behavior may also become relevant depending on how the final command is constructed. The Skill is intended to process links matching `mp.weixin.qq.com/s/`, but the document does not impose an explicit URL-parsing, hostname-validation, character-validation, or shell-escaping requirement before invoking `exec`. Consequently, relying on the intended trigger alone does not establish a security boundary. This use of `exec` exceeds the minimum privileges required for the declared article retrieval and summarization functionality because the Skill already allows `web_fetch`, which can retrieve content without constructing a sh ...[truncated 1980 chars]- Remediation
View remediation
