T09 · Insecure Skill Coding Practices
- Location
SKILL.md:22- Finding
Command and Python Code Injection Through Unsafely Interpolated Inputs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This password-hashing skill has a coherent purpose, but its instructions handle passwords through unsafe inline shell commands that can expose secrets or execute injected input.
Review before installing. Do not use this skill with real production passwords as written. A safer version should read the password from standard input, parse rounds as an integer, avoid shell interpolation, validate hashes, and avoid temporary files or command lines that contain secrets.
SKILL.md:22Command and Python Code Injection Through Unsafely Interpolated Inputs
SKILL.md:22Plaintext Password Exposure Through Process Command Lines and Temporary Scripts
SKILL.md:43Unpinned Third-Party Dependency Installation Instruction
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
> "This skill requires the Python `bcrypt` package. Install with: `pip3 install bcrypt`."
5. If `python3` is not found at all, tell the user:
> "This skill requires `python3`. Install with: `brew install python3` (macOS) or `sudo apt install python3` (Linux)."
6. Present the hash output on its own line. For verification, report clearly: "Password MATCHES the hash" or "Password does NOT match the hash."
No suspicious patterns detected.