T09 · Insecure Skill Coding Practices
- Location
SKILL.md:17- Finding
Unvalidated Target Substitution Can Enable Shell Command Injection
- Content
View full analysis
/tmp/nmap-skill-proof # ``` into the fast-scan template would produce: ```bash nmap -F -T4 127.0.0.1; id > /tmp/nmap-skill-proof # ``` The shell would run both Nmap and the injected `id` command. The issue is especially sensitive around the documented `sudo` profiles. An injected command is not automatically elevated merely because `sudo nmap` appears earlier in the command; however, unsafe command construction combined with a privileged agent pro ...[truncated 1804 chars]- Remediation
View remediation
