T09 · Insecure Skill Coding Practices
- Location
skill.md:105- Finding
Insufficient Validation and Unsafe Shell Interpolation of User-Controlled Arguments
- Content
View full analysis
30s): ```bash ffmpeg -i input.mp4 -ss -to -c:v libx264 -c:a aac /tmp/verging-faceswap/trimmed.mp4 ``` ``` ### Technical Analysis The Skill directs the Agent to place user-provided video URLs, image URLs, and trim values into command-line operations without requiring strict validation. Although the example URLs are enclosed in quotes, the instructions do not restrict URL schemes, resolve and validate destinations, impose download limits, or verify that redirects remain on public networks. In particular, `curl -L` follows redirects and can retrieve resources from destinations selected by the user. This may permit access to loopback, private-network, link-local, or local-file resources, depending on the schemes and network access available to the installed client. The `` and `` values are also inserted into a shell command without a requirement that they be parsed as bounded numeric values. If an implementation constructs a shell command by textual substitution, shell metacharacters or malicious option values may cause command or argument injection. No file-size, media-type, or resource-consumption limits are prescribed before untrusted content is passed to `ffmpeg`, `ffprobe`, or `yt-dlp`. ### Attack Path 1. An attacker invokes `/faceswa ...[truncated 1614 chars]- Remediation
View remediation
= 0` - `end > start` - `end - start <= 30` - A reasonable maximum absolute duration 2. Execute external programs with argument arrays and without a command shell. Never construct commands through textual concatenation or substitution. 3. Insert `--` before positional file arguments where the target utility supports it, and reject ambiguous values beginning with `-`. 4. Allow only explicitly supported URL schemes, preferably `https`. 5. Resolve destination hostnames and reject loopback, link-local, multicast, private, reserved, and cloud-metadata address ranges for every redirect. 6. Limit redirect count, download size, transfer time, and bandwidth. 7. Validate downloaded files using magic bytes and trusted media parsers rather than relying on extensions or response `Content-Type`. 8. Run media-processing tools in a restricted sandbox with limited filesystem access, network access, CPU time, memory, and output size. 9. Require explicit user confirmation before uploading any resource fetched from a user-provided URL to a third-party service. ]]>
