T09 · Insecure Skill Coding Practices
- Location
scripts/upload.sh:49- Finding
Arbitrary Python Code Execution Through Unsafe unique_id Interpolation
- Content
View full analysis
1 else "", "create_time": '"$CREATE_TIME"', "status": 1, "is_collect": 0, "is_todo": 0 ``` `scripts/update.sh:51-58`: ```bash import json, sys print(json.dumps({ "unique_id": "'"$UNIQUE_ID"'", "type": 1, "content": sys.argv[1] if len(sys.argv) > 1 else "", "status": 1, "is_collect": 0, "is_todo": 0 })) ``` ### Technical Analysis Both scripts insert the shell variable `UNIQUE_ID` directly into the source code supplied to `python3 -c`. Although the intended result is a Python string literal, no escaping or serialization is applied before the value becomes executable Python source. An attacker-controlled identifier containing quotes and Python expressions can terminate or alter the intended string expression. For example, an identifier shaped like the following can cause an operating-system command to execute while the dictionary is evaluated: ```text " + str(__import__("os").system("id")) + " ``` This is distinct from ordinary shell argument injection: the shell passes the value into the generated Python program, and the Python interpreter subsequently treats parts of the value as source code. The update workflow is particularly exposed because `unique_id` may originate from a user instruction or an API search result. The upload script also permits the caller to supply an optional `unique_id`. ### Attack Path 1. An attacker supplies a malicious `unique_id`, either directly in a user request or indirectly through untrusted data that the Agent treats as a note identifier. 2. The Agent invokes one of the affected comman ...[truncated 1259 chars]- Remediation
View remediation
