T09 · Insecure Skill Coding Practices
- Location
ling-shu-agent-designer/SKILL.md:363- Finding
Unsanitized Release Parameters and Destructive Forced Publication
- Content
View full analysis
.skill / # 2. Push to GitHub cd /tmp/lingshu-agent-architect git add . git commit -m "Release v: " git push -u origin main --force # 3. Publish to ClawHub clawhub publish --slug lingshu-agent-architect \ --name "Ling Shu Agent Designer" \ --version ``` ### Technical Analysis The release workflow instructs the agent to interpolate a skill name, version, and update description directly into shell commands. It does not require validation, shell-safe quoting, or an argument-array execution API. The following parameters are unsafe: - `` appears unquoted in both the output archive name and source path. - `` is inserted into a double-quoted shell argument. Embedded quotation marks, command substitutions, backticks, or shell metacharacters could escape the intended commit message. - `` is passed unquoted to both Git and ClawHub-related commands. - The workflow uses a predictable shared directory under `/tmp`, without verifying ownership, rejecting symbolic links, or checking the repository remote. - `git add .` stages every file in the working tree rather than an explicit allowlist of reviewed files. - `git push ... --force` can overwrite the remote `main` branch and destroy commits that are not present in the local checkout. The requirement to show a diff and obtain confirmation reduces accidental publication risk, but it does not neutralize shell metacharacters, detect a substituted temporary repository, prevent a time-of-check/time-of-use modification after review, or make the forced push safe. ### Attack Path 1. An attacker suppl ...[truncated 2083 chars]- Remediation
View remediation
