T09 · Insecure Skill Coding Practices
- Location
SKILL.md:47- Finding
Shell Command Injection Through an Unsanitized Agent Name
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47–56
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable code snippet:
markdown When user wants to create an agent: 1. Ask for agent name and purpose (don't mention "templates") 2. Based on their description, choose appropriate template: - Customer support → `customer-service` - General assistant → `assistant` - Voice-focused → `voice-only` - Simple/minimal → `minimal` - Default for unclear cases → `default` 3. Run: `elevenlabs agents add "Name" --template <template>`Technical Analysis
The skill directs the agent to collect an attacker-controlled agent name and insert it into a quoted CLI command. It does not require validation, shell-safe escaping, or execution through a structured argument array.
Double quotes do not provide adequate protection when untrusted input can itself contain quotes, command substitutions, or shell control operators. If the agent constructs the documented command as a string and passes it to a shell, a malicious name can terminate the quoted argument and append another command.
For example, an agent name shaped like the following benign proof of concept would escape the intended argument:
text x"; id; echo "Interpolation would produce a command equivalent to:
bash elevenlabs agents add "x"; id; echo "" --template defaultThe shell would consequently execute
idindependently of the ElevenLabs CLI. The issue is not inherent to the ElevenLabs CLI; it arises from constructing a shell command by interpolating untrusted input.Attack Path
- An attacker asks the skill to create an ElevenLabs agent.
- The attacker supplies an agent name containing a closing quote and shell control operators.
- The AI agent substitutes that name into the documented command template.
- The resulting command string is submitted to a shel ...[truncated 1203 chars]
- Remediation
View remediation
Remediation Suggestions
-
Invoke the ElevenLabs CLI through a process API that accepts an executable and argument array, without a shell. For example, pass arguments conceptually as:
text ["agents", "add", userSuppliedName, "--template", validatedTemplate] -
Explicitly prohibit command construction through string concatenation, interpolation,
shell=True,sh -c,bash -c, or equivalent shell wrappers. -
Validate agent names using a documented policy:
- Enforce a reasonable maximum length.
- Reject control characters and line breaks.
- Prefer an allowlist of letters, digits, spaces, hyphens, and underscores where compatible with ElevenLabs.
- Return a validation error instead of silently transforming ambiguous input.
-
Select template values exclusively from the fixed allowlist documented by the skill. Never accept an arbitrary template string from the user.
-
Update the instruction to state that user-provided values must be passed as literal process arguments and must never be interpolated into a shell command.
-
Add security tests using names containing quotes, semicolons, command substitutions, backticks, newlines, and option-like prefixes to verify that they cannot create additional commands or alter CLI arguments.
-
