T09 · Insecure Skill Coding Practices
- Location
SKILL.md:58- Finding
Unsafe Shell Interpolation and Unrestricted Retrieval of Untrusted URLs
- Content
View full analysis
" | python3 -c " import sys, re html = sys.stdin.read() # Strip tags, get text text = re.sub('<[^>]+>', ' ', html) text = re.sub(r'\s+', ' ', text).strip() print(text[:5000]) " ``` ### Technical Analysis The Skill instructs the Agent to insert a URL obtained from search results into a shell command. Although the placeholder is enclosed in double quotes, double-quoted shell strings still process command substitutions such as `$()` and backticks. If an untrusted URL is copied verbatim into this template, shell metacharacters within that value could cause commands to run locally with the privileges of the Agent process. The command also invokes `curl` with `-L`, permitting redirects, without restricting destination schemes, resolved addresses, redirect targets, response size, or request duration. An attacker-controlled URL could therefore redirect the request to loopback, private-network, link-local, or cloud metadata services. This can expose resources that are inaccessible to an external attacker but reachable from the Agent's environment. The downloaded response is passed to fixed Python code as standard input and is not itself interpreted as Python or shell code. Therefore, this is not a confirmed remote-payload execution pattern based solely on response content. The risk instead arises from unsafe URL interpolation and unrestricted outbound retrieval. ### Attack Path 1. An attacker supplies a crafted URL directly in a research request or publishes a page that becomes visible in search results. 2. The Agent selects that URL as one of the sources to read. 3. The Agent substitutes the URL verbatim into the documented shell template. 4. A URL containing shell command substitution syntax causes the shell to execute an attack ...[truncated 1520 chars]- Remediation
View remediation
