T09 · Insecure Skill Coding Practices
- Location
scripts/install_ga4_openclaw.sh:27- Finding
Arbitrary Code Execution Through Property ID Injection
- Content
View full analysis
" client.json ``` 3. The installer interpolates the malicious value into the Python heredoc. 4. The value terminates the intended Python string and inserts an attacker-controlled Python statement. 5. Python executes the injected comm ...[truncated 698 chars]- Remediation
View remediation
&2 exit 1 fi ``` 2. Use a quoted heredoc so that Bash does not expand its contents. 3. Pass values to Python through environment variables or command-line arguments instead of constructing Python source dynamically: ```bash PROPERTY_ID="$PROPERTY_ID" SHELL_RC="$SHELL_RC" python3 - <<'PY' import os import re from pathlib import Path property_id = os.environ["PROPERTY_ID"] rc = Path(os.environ["SHELL_RC"]) text = rc.read_text() if rc.exists() else "" text = re.sub(r"^export GA4_PROPERTY_ID=.*\n?", "", text, flags=re.M) if text and not text.endswith("\n"): text += "\n" text += f'export GA4_PROPERTY_ID="{property_id}"\n' rc.write_text(text) print(f"Updated {rc}") PY ``` 4. Add automated tests using values containing quotes, newlines, semicolons, command substitutions, and Python expressions to verify that malformed identifiers are rejected. ]]>
