T09 · Insecure Skill Coding Practices
- Location
scripts/generate_custom_statusline.sh:52- Finding
Arbitrary Command Execution Through Unsafe Custom Statusline Generation
- Content
View full analysis
> "$TARGET_PATH" # ---- cc-statusline custom layout override ---- export CC_STATUSLINE_CUSTOM_LAYOUT_MODE=true export CC_STATUSLINE_CUSTOM_THEME="${THEME}" export CC_STATUSLINE_CUSTOM_ICON_STYLE="${ICON_STYLE}" export CC_STATUSLINE_CUSTOM_LINE_1="${LINE_1}" export CC_STATUSLINE_CUSTOM_LINE_2="${LINE_2}" export CC_STATUSLINE_CUSTOM_LINE_3="${LINE_3}" EOF ``` ### Technical Analysis `THEME`, `ICON_STYLE`, and the three layout values originate from command-line arguments and are embedded directly into an executable Bash script. The values are neither strictly validated nor encoded as shell literals. An attacker-controlled value can contain shell syntax such as command substitution, closing quotation marks, or newline-delimited commands. For example, a layout value containing `$(attacker_command)` would produce a generated line similar to: ```bash export CC_STATUSLINE_CUSTOM_LINE_1="$(attacker_command)" ``` When the generated statusline is later executed, Bash evaluates the command substitution. A newline can similarly escape the intended assignment and add independent shell statements. This is particularly significant because `activate_custom_statusline.sh` stores the generated script as Claude Code's `statusLine.command`. Consequently, the injected payload may execute whenever Claude Code refreshes the statusline, rather than only during initial generation. The generated assignments are appended after the complete runtime script. The normal preset rendering path in `statusline.sh` does not terminate with an explicit `exit`, so Bash continues into the appended content and evaluates injected shell syntax. ### Attack Path 1. An attacker influences a module list, theme, icon style, or command supplied to ...[truncated 1200 chars]- Remediation
View remediation
> "$TARGET_PATH" ``` 4. Prefer storing customization in JSON and parsing it as data rather than generating executable shell source. 5. Generate configuration before runtime execution, or pass validated data as arguments, instead of appending executable statements to the end of the runtime script. 6. Refuse to overwrite an existing unmanaged target file without explicit confirmation and create a backup before replacement. 7. Add regression tests using quotes, command substitutions, backticks, semicolons, and multiline input to verify that none can produce executable statements. ]]>
