T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
Shell Command Injection Through Untrusted JSON Data
- Content
View full analysis
'' ``` ### Technical Analysis The skill instructs the agent to place image-derived, user-controlled JSON directly inside a shell command. Wrapping the JSON in single quotes does not make this safe because a cell value can itself contain a single quote. If the agent follows this command template literally, an attacker can place shell metacharacters in table text, terminate the quoted JSON argument, append another command, and comment out the remainder. JSON encoding does not inherently escape characters for safe interpolation into a POSIX shell command. For example, extracted content containing a value structurally similar to the following could break the shell quoting: ```text '; attacker_command; # ``` The issue exists in the documented execution workflow even though `gen_excel.py` itself does not invoke a shell for this data. ### Attack Path 1. An attacker prepares an image containing table text with a single quote followed by shell syntax. 2. The image extraction model preserves the malicious text in the generated JSON array. 3. The agent substitutes that JSON directly for `` in the documented command. 4. The embedded single quote terminates the shell argument. 5. The shell interprets the remaining text as a separate command. 6. The injected command executes with the operating-system privileges and environment access of the agent process. ### Impact Assessment Successful exploitation can provide arbitrary command execution under the account running the skill. The attacker could read or modify files accessible to that account, alter generated artifacts, access environment variables, invoke network utilities, or execute additional local programs. The precise scope is limited by the privileges, sandboxing, filesystem a ...[truncated 51 chars]- Remediation
View remediation
