T09 · Insecure Skill Coding Practices
- Location
scripts/add_comment.sh:27- Finding
Unescaped User Input in JSON Comment Payload
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi COMMENT_JSON=$( jq -n \ --arg task_id "$TASK_ID" \ --arg content "[$TIMESTAMP] $COMMENT" \ '{task_id: $task_id, content: $content}' ) ``` Additional hardening measures: 1. Validate task identifiers against the exact format required by the Todoist API. 2. Retain `jq --arg` encoding for all externally supplied string values. 3. Reject invalid input before making a network request. 4. Use `curl --fail-with-body --show-error --silent` so HTTP failures produce a nonzero exit status. 5. Print the success message only after confirming a successful HTTP response. ]]>
