T09 · Insecure Skill Coding Practices
- Location
SKILL.md:23- Finding
Shell Command Injection Through Unescaped Directory and File Commands
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:23andSKILL.md:28
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable code:
text 3. Create subdirs if needed: Extract parent from rel_path; call 'exec'("mkdir -p [base_dir]/[parent]") or message: "Please run `mkdir -p [full_parent]` and confirm."text 7. If tools fail, fallback: Message requesting user runs `echo "[content]" > [full_path]` or `>>` for append.Technical Analysis
The workflow interpolates user-controlled path components into a shell command passed to
exec. Its validation only rejects absolute paths, parent traversal, and selected file extensions. It does not reject or safely encode shell metacharacters, quotes, command substitution expressions, newlines, or other shell syntax.For example, a relative parent directory containing command separators or command substitution syntax could still satisfy the documented path checks. If inserted into the
mkdir -pcommand and interpreted by a shell, the additional syntax would be executed rather than treated as a literal directory name.The fallback command has a similar defect: untrusted file content is placed inside a double-quoted
echocommand. Quotes, command substitutions, and shell syntax in the supplied content may break the intended command boundary. Although this fallback is presented to the user rather than necessarily executed by the Agent, it still generates an unsafe command that could lead to code execution if followed.Attack Path
- An attacker requests a write to a relative path whose parent contains shell syntax while retaining an allowed extension.
- The path passes the documented checks because it does not begin with
/, contain../, or use a prohibited extension. - The workflow constructs
mkdir -p [base_dir]/[parent]by direct string interpolation. - The command is passed to a shell-backed
execimplementation. 5 ...[truncated 834 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not construct shell commands by concatenating user-controlled values.
- Create directories through a dedicated filesystem API.
- If a subprocess is unavoidable, pass arguments as an array with shell interpretation disabled, such as
shell=false. - Apply strict path-component validation in addition to canonical containment checks.
- Remove the
echofallback. Write content through a filesystem API that accepts content separately from the destination path. - If command generation is unavoidable, use a rigorously reviewed encoding mechanism and never embed untrusted content directly in shell source.
- Reject control characters, newlines, shell metacharacters, and ambiguous path components as defense in depth.
