T09 · Insecure Skill Coding Practices
- Location
SKILL.md:47- Finding
Unsafe Shell Interpolation Guidance for User-Controlled Note Names
- Content
View full analysis
→ note_id 3. → gkeep.py get → show content 4. User: "Add milk to " 5. → gkeep.py list | grep → note_id 6. → gkeep.py add "milk" ``` ### Technical Analysis The documented workflow directs the agent to place a note name derived from the user's request into a shell pipeline involving `grep`. It does not require argument-array execution, robust quoting, an end-of-options marker, or validation of shell metacharacters. If an agent substitutes the supplied note name directly into the command, characters such as command substitutions, semicolons, pipes, or redirections may be interpreted by the shell rather than treated as literal search text. Although the Python CLI does not itself invoke a shell, the skill instructions establish an unsafe execution pattern that an agent may follow. ### Attack Path 1. An attacker requests access to a note whose alleged name contains shell syntax. 2. The agent follows the documented workflow and substitutes that value into `gkeep.py list | grep `. 3. The generated command is passed to a shell without safe argument separation. 4. The shell interprets the embedded syntax. 5. An attacker-selected local command executes with the same operating-system privileges as the agent process. Exploitation depends on the calling agent performing direct shell interpolation as suggested by the workflow. ### Impact Assessment Successful exploitation could permit arbitrary command execution under the account running the skill. This may expose local files, the Google Keep master token stored under `~/.config/gkeep/token.json`, environment variables, and other credentials available to the agent. It may also allow local file modification or execut ...[truncated 137 chars]- Remediation
View remediation
