T09 · Insecure Skill Coding Practices
- Location
scripts/guard.sh:82- Finding
Arbitrary Command Execution Through Untrusted Service Configuration
- Content
View full analysis
/dev/null 2>&1 return $? ;; *) log_warn "未知检测类型: $check_type" return 1 ;; esac return 1 } # 执行修复 do_fix() { local name="$1" local fix_cmd="$2" log_info "[$name] 执行修复..." eval "$fix_cmd" 2>&1 | while read line; do log " $line" done } # 执行回滚 do_rollback() { local name="$1" local rollback_cmd="$2" local backup_dir="$3" # 自动备份(如果指定了备份目录) if [[ -n "$backup_dir" && -f "$CONFIG_FILE" ]]; then mkdir -p "$backup_dir" # 这里需要根据实际情况备份对应服务的配置文件 # 通用回滚依赖用户自定义 rollback 命令 fi if [[ -z "$rollback_cmd" ]]; then log_warn "[$name] 未定义回滚命令,跳过" return 1 fi log_warn "[$name] 执行回滚..." eval "$rollback_cmd" 2>&1 | while read line; do log " $line" done } ``` The affected values originate directly from the configuration at `scripts/guard.sh:153-155`: ```bash local fix_cmd=$(echo "$service" | jq -r '.fix') local rollback_cmd=$(echo "$service" | jq -r '.rollback // empty') local timeout=$(echo "$service" | jq -r '.timeout // 5') ``` The custom health-check command similarly comes from `.check.command` in the supplied JSON service object. ### Technical Analysis The script treats JSON configuration fields as shell source code and evaluates them with `eval`. Consequently, shell operators, command substitutions, redirections, pipelines, variable expansions, and chained commands contained in the configuration are interpreted by the shell. The vulnerable execution sinks cover three paths: 1. A custom `cmd` health check. 2. The `fix` ac ...[truncated 2748 chars]- Remediation
View remediation
