T09 · Insecure Skill Coding Practices
- Location
scripts/kapsel.py:31- Finding
Arbitrary Command Execution Through Shell Command Injection
- Content
View full analysis
/dev/null") summary, _ = run( f'rclone cat "{KAPSELN_REMOTE}/{name}/summary.md" 2>/dev/null' ) out, err = run( f'rclone copy "{LOCAL_TMP}/{name}" "{KAPSELN_REMOTE}/{name}/"' ) details, _ = run( f'rclone cat "{KAPSELN_REMOTE}/{name}/details.md" 2>/dev/null' ) context, _ = run( f'rclone cat "{KAPSELN_REMOTE}/{name}/context.md" 2>/dev/null' ) files, _ = run( f'rclone ls "{KAPSELN_REMOTE}/{name}/files/" 2>/dev/null' ) out, err = run( f'rclone copy "{filepath}" "{KAPSELN_REMOTE}/{name}/files/"' ) ``` The affected values originate from command-line arguments or environment variables: ```python KAPSELN_REMOTE = os.environ.get("KAPSEL_REMOTE", "gdrive:Kapseln") LOCAL_TMP = os.environ.get("KAPSEL_TMP", "/tmp/openclaw/kapseln") name = sys.argv[2] filepath = sys.argv[3] ``` ### Technical Analysis The `run` function passes a constructed string to `subprocess.run` with `shell=True`. Consequently, `/bin/sh` parses metacharacters and performs command substitution, variable expansion, redirection, and command chaining. Adding double quotes around an interpolated value does not make it safe. Sh ...[truncated 1790 chars]- Remediation
View remediation
/dev/null`; use `stderr=subprocess.DEVNULL` where suppression is genuinely required. 5. Check `returncode` instead of searching stderr for the word `error`. 6. Add tests using names and paths containing spaces, quotes, dollar signs, backticks, semicolons, and command substitutions to verify that none are interpreted by a shell. ]]>
