T09 · Insecure Skill Coding Practices
- Location
SKILL.md:143- Finding
Shell Command Injection Through User-Controlled Subscription Keywords
- Content
View full analysis
` - 执行频率:每天 10:00(cron `0 10 * * *`) - 执行命令:`python3 <脚本路径>/search_douyin.py "<关键词>"`(有时间参数则附加 `--start-date`/`--end-date`) - 通用 crontab:`0 10 * * * python3 /path/to/search_douyin.py "<关键词>"` ``` Related execution templates: ```bash python3 ~/.qoderwork/skills/douyin-search/scripts/search_douyin.py "<关键词>" python3 ~/.qoderwork/skills/douyin-search/scripts/search_douyin.py "<关键词>" --start-date --end-date ``` ### Technical Analysis The Skill instructs the Agent to interpolate a user-derived search keyword directly into a shell command and, for subscriptions, into a persistent crontab entry. Enclosing the keyword in double quotes does not make it safe for shell evaluation. Shell command substitution using `$()` or backticks remains active inside double quotes, and an embedded quote can terminate the quoted argument and introduce additional shell operators. The Python script itself does not invoke a shell and safely serializes its received keyword into JSON. The vulnerability arises before Python starts, when the Agent or scheduling platform constructs and executes the documented shell command. The scheduled task is relevant to the declared daily-subscription functionality and requires an explicit confirmation response, so persistence is not inherently unauthorized. Nevertheless, unsafe interpolation allows attacker-controlled shell instructions to be installed persistently. In addition, the supplied Python script only prints JSON and contains no notification-delivery implementation, meaning the documented cron command does not independently fulfill the promised push-notification behavior. ...[truncated 1883 chars]- Remediation
View remediation
