T09 · Insecure Skill Coding Practices
- Location
SKILL.md:34- Finding
User-Controlled Query Interpolated into a Shell Command
- Content
View full analysis
--list all --log_question "<用户的原始问题>" ``` The surrounding instructions explicitly require the command to include the user's original question: ```text **务必带上 --log_question 参数**:它会在读目录的同时把本次查询写入 log.md。 ``` ### Technical Analysis The Skill instructs the Agent to place the original, untrusted user question directly inside a shell command. Enclosing the value in double quotes is not sufficient shell escaping. Characters such as embedded double quotes, command substitutions (`$(...)`), backticks, and some shell expansions may alter command interpretation before Python receives the argument. Although `kb_read.py` processes the resulting argument through `argparse`, that protection only applies after the shell has parsed the command. An attacker can therefore target the shell invocation itself. Exploitability depends on whether the Skill runtime executes the documented command through a shell and whether it performs independent argument escaping. The Skill instructions do not require a shell-free invocation or define a safe encoding mechanism. ### Attack Path 1. An attacker asks a knowledge-base question containing shell metacharacters or command substitution. 2. The Agent follows `SKILL.md` and inserts the original question into the documented command. 3. The runtime passes the constructed command to a shell. 4. The shell interprets the attacker-controlled syntax before launching `kb_read.py`. 5. The injected command executes with the permissions of the Agent or Skill process. 6. The attacker may use that access to read `.env`, recover the Gitea administrator token, modify local files, or send data to an external destination. ### Impact Assessment Successful exploitation provides arbitrary command execution ...[truncated 392 chars]- Remediation
View remediation
