T09 · Insecure Skill Coding Practices
- Location
SKILL.md:27- Finding
Shell Command Injection Through User-Controlled Ledger Arguments
- Content
View full analysis
--amount --note "" ``` ### Technical Analysis The Skill instructs the agent to interpolate values parsed from natural-language user input directly into a shell command. The `role` value is not quoted at all, and the `note` value can escape its double-quoted context by including a quotation mark. No instruction requires shell-safe escaping, strict validation, or invocation through a structured argument-array API. The parameterized SQLite queries in `ledger.py` prevent SQL injection, but they do not prevent this vulnerability because shell parsing occurs before `ledger.py` receives the arguments. For example, a malicious role resembling the following could introduce an additional command: ```text father; python3 -c 'ATTACKER_CONTROLLED_PYTHON' # ``` When directly substituted into the documented template and executed through a shell, the resulting command would resemble: ```bash python3 /home/ubuntu/projects/record-family/ledger.py add --role father; python3 -c 'ATTACKER_CONTROLLED_PYTHON' # --amount 100 --note "groceries" ``` The shell would treat the semicolon as a command separator and execute the injected Python command independently. ### Attack Path 1. An attacker submits a natural-language ledger request containing shell metacharacters in the role or purpose. 2. The agent identifies the request as an expense-recording operation. 3. Following the Skill instructions, the agent inserts the attacker-controlled values into the documented command string. 4. The agent sends the constructed string to a shell execution tool. 5. The shell interp ...[truncated 957 chars]- Remediation
View remediation
