T09 · Insecure Skill Coding Practices
- Location
scripts/compress.js:35- Finding
Shell Command Injection Through User-Controlled Arguments
- Content
View full analysis
`"${path.resolve(f)}"`).join(' '); const outputPath = `"${path.resolve(outputFile)}"`; try { execSync(`img2pdf ${inputPaths} -o ${outputPath}`, { stdio: 'pipe' }); } catch { console.log('img2pdf unavailable; trying ImageMagick...'); try { execSync(`convert ${inputPaths} ${outputPath}`, { stdio: 'pipe' }); ``` `scripts/merge.js:25-32`: ```javascript const inputPaths = inputFiles.map(f => `"${path.resolve(f)}"`).join(' '); const outputPath = `"${path.resolve(outputFile)}"`; const command = `gs -dBATCH -dNOPAUSE -q -sDEVICE=pdfwrite -sOutputFile=${outputPath} ${inputPaths}`; try { execSync(command, { stdio: 'inherit' }); ``` `scripts/pdf2img.js:20-38`: ```javascript const inputPath = path.resolve(inputFile); const baseName = path.parse(inputFile).name; const dpi = options.dpi || 150; const format = options.format || 'png'; const outputPath = path.join(outputDir, baseName); try { let command; if (format === 'png') { command = `pdftoppm -png -r ${dpi} "${inputPath}" "${outputPath}"`; } else if (format === 'jpg') { command = `pdft ...[truncated 3910 chars]- Remediation
View remediation
