T09 · Insecure Skill Coding Practices
- Location
baidu_scholar_search.sh:13- Finding
Unescaped Search Input Permits JSON Request-Body Injection
- Content
View full analysis
Vulnerability Details
File Location:
baidu_scholar_search.sh, lines 13–26
Vulnerability Type: JSON injection caused by unsafe string interpolation
Risk Level: MediumVulnerable Code
bash WD="$1" if [ -z "$WD" ]; then echo '{"error": "Missing wd parameter"}' exit 1 fi pageNum="${2:-0}" enable_abstract="${3:-false}" curl -s -X POST \ -H "Authorization: Bearer $SKILLBOSS_API_KEY" \ -H "Content-Type: application/json" \ -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \ "https://api.heybossai.com/v1/pilot"The same vulnerable implementation is reproduced in
SKILL.md, lines 57–72.Technical Analysis
The script inserts the user-controlled
WDargument directly into a manually assembled JSON string. Shell quoting prevents word splitting and direct shell-command substitution after parameter expansion, so this is not a demonstrated shell-command injection vulnerability. However, shell quoting does not JSON-escape quotation marks, backslashes, or control characters contained inWD.An attacker can therefore supply JSON syntax that terminates the intended
querystring and introduces additional properties or structures. Alternatively, malformed input can invalidate the entire request. The resulting body is sent to the remote API using the legitimateSKILLBOSS_API_KEY.The exact server-side effect depends on the API parser, schema validation, and supported properties. Modification of fields not shown in the audited client cannot be asserted, but the client demonstrably fails to preserve the input solely as a JSON string value.
Attack Path
- An attacker or untrusted caller invokes the script with a search term containing quotation marks and JSON syntax.
- The script assigns this content to
WDwithout JSON encoding or validation. - The
-dargument interpolates the content verbatim into the JSON document. - The crafted content terminates or modifies the intend ...[truncated 874 chars]
- Remediation
View remediation
Remediation Suggestions
Construct the request body with a JSON serializer rather than manual string concatenation. For example, if
jqis declared and installed as a dependency:bash payload=$(jq -n --arg query "$WD" \ '{type: "search", inputs: {query: $query}, prefer: "balanced"}') curl --fail-with-body -sS -X POST \ -H "Authorization: Bearer $SKILLBOSS_API_KEY" \ -H "Content-Type: application/json" \ --data-binary "$payload" \ "https://api.heybossai.com/v1/pilot"This ensures that quotes, backslashes, control characters, Unicode content, and line breaks are encoded as JSON string data rather than interpreted as JSON structure.
Additional hardening should include:
- Declare
jqas a required binary if this implementation is adopted. - Apply a reasonable maximum length to
WDto limit oversized requests and quota abuse. - Use
curl --fail-with-body -sSso transport and HTTP failures are observable. - Validate and implement
pageNumandenable_abstract, or remove them from the interface to avoid misleading callers. - Update the duplicated implementation in
SKILL.mdso documentation does not encourage reuse of the vulnerable pattern. - Add tests containing quotes, backslashes, newlines, and JSON-like input to verify that each value remains confined to
inputs.query.
- Declare
