T09 · Insecure Skill Coding Practices
- Location
src/core/scanner.ts:97- Finding
Manifest-Controlled Dependency Names Permit Shell Command Injection
- Content
View full analysis
/dev/null`, { encoding: "utf-8", timeout: 10000 }).trim(); if (out) detectedLicense = normalizeSpdx(out); } catch { /* offline or not found */ } } ``` ```ts // pip dependencies if (!offline) { try { const out = execSync(`pip show ${name} 2>/dev/null`, { encoding: "utf-8", timeout: 10000 }); const match = out.match(/^License:\s*(.+)$/m); if (match) detectedLicense = normalizeSpdx(match[1]); } catch { /* skip */ } } ``` ```ts // Cargo dependencies if (!offline) { try { const out = execSync(`cargo info ${name} 2>/dev/null`, { encoding: "utf-8", timeout: 10000 }); const lMatch = out.match(/license:\s*(.+)/i); if (lMatch) detectedLicense = normalizeSpdx(lMatch[1]); } catch { /* skip */ } } ``` The same vulnerable behavior is present in the shipped runtime artifact at `dist/core/scanner.js:73`, `dist/core/scanner.js:115`, and `dist/core/scanner.js:152`. ### Technical Analysis `execSync()` executes string commands through a shell. Dependency names are obtained from repository-controlled files, including `package.json`, `requirements.txt`, and `Cargo.toml`, and are interpolated directly into these command strings. No ecosystem-specific validation, shell escaping, or argument separation is performed. A dependency name containing shell metacharacters such as command separators, substitutions, or redirections can therefore change the command executed by the shell. Suppressing standard error with `2>/dev/null` does not mitigate command injection and may make exploitation less visible. C ...[truncated 1351 chars]- Remediation
View remediation
