T09 · Insecure Skill Coding Practices
- Location
scripts/Spawn-app.sh:12- Finding
Frida Argument and Script-Path Injection in Spawn Launcher
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi cmd=(frida -U -f "$package") if [[ -n "$script" ]]; then base_dir=$(realpath -- "$FRIDA_SCRIPT_DIR") || exit 1 script_path=$(realpath -- "$FRIDA_SCRIPT_DIR/$script") || exit 1 case "$script_path" in "$base_dir"/*) ;; *) echo "Script path is outside the permitted directory" >&2 exit 1 ;; esac [[ -f "$script_path" ]] || exit 1 cmd+=(-l "$script_path") fi "${cmd[@]}" ``` Where practical, accept only a fixed allowlist of bundled Frida scripts rather than arbitrary paths. ]]>
