T09 · Insecure Skill Coding Practices
- Location
SKILL.md:21- Finding
Shell Command Injection Through Unsafely Interpolated Magnet URL
- Content
View full analysis
" ``` ### Technical Analysis The skill instructs the agent to replace `` with a user-provided magnet URI and then execute the resulting command through a shell. The value is embedded directly inside a double-quoted shell argument without shell-safe encoding. Double quotes do not provide adequate protection when untrusted data is inserted through textual replacement. A malicious value can include a double quote to terminate the intended argument, followed by shell syntax such as command substitution, backticks, separators, or redirections. The shell may then interpret that syntax as commands rather than treating the entire value as browser input. Requiring the value to begin with `magnet` is insufficient because an attacker can place malicious shell syntax after a valid-looking prefix. The vulnerability is reached specifically when the agent performs the documented placeholder substitution and executes the generated shell command. ### Attack Path 1. An attacker supplies a crafted value that begins with a plausible `magnet:` prefix but also contains a quote and shell syntax. 2. The agent follows the skill instructions and replaces `` verbatim with the supplied value. 3. The replacement closes the double-quoted argument in the generated shell command. 4. The shell interprets the remaining attacker-controlled characters as shell syntax. 5. The injected command executes with the operating-system privileges of the account running the agent or `openclaw`. 6. The original command may then continue, fail, or be syntactically repaired by additional attacker-controlled characters, potentially conceal ...[truncated 749 chars]- Remediation
View remediation
