T09 · Insecure Skill Coding Practices
- Location
scripts/ssh-run-native.sh:353- Finding
Plaintext sudo password exposed through command arguments and JSON output
- Content
View full analysis
' | sudo -S -p '' -- sh -c "$(echo '' | base64 -d)" ENCODED_CMD=$(printf '%s' "$REMOTE_COMMAND" | base64 -w0) REMOTE_COMMAND="echo '${SUDO_PASS}' | sudo -S -p '' -- sh -c \"\$(echo '${ENCODED_CMD}' | base64 -d)\"" else ORIGINAL_COMMAND="$REMOTE_COMMAND" fi # Dangerous command check if is_dangerous_command "$REMOTE_COMMAND" && [[ "$CONFIRM_DANGEROUS" -ne 1 ]]; then python3 - "$HOST" "$REMOTE_COMMAND" <<'PY' import json, sys host, cmd = sys.argv[1:] print(json.dumps({ "success": False, "exit_code": 99, "dangerous": True, "heuristic_match": True, "error": "Command looks mutating or destructive. Re-run with --confirm-dangerous only after explicit user approval.", "host": host, "command": cmd, })) PY exit 99 fi ``` The wrapped command is subsequently supplied as a process argument: ```bash $SSH_BIN "${SSH_ARGS[@]}" -G "$TARGET" >"$RESOLVED_FILE" 2>/dev/null RESOLVE_EXIT=$? $SSH_BIN "${SSH_ARGS[@]}" "$TARGET" "$REMOTE_COMMAND" >"$STDOUT_FILE" 2>"$STDERR_FILE" EXIT_CODE=$? ``` ### Technical Analysis The resolved sudo password is interpolated directly into `REMOTE_COMMAND`. This causes the plaintext credential to cross multiple unsafe boundaries: 1. The password becomes part of the local `ssh` process argument vector. 2. It may become visible to process inspection, monitoring, crash diagnostics, audit tooling, or other users with sufficient `/proc` access. 3. If `--confirm-dangerous` is absent, the dangerous-command rejection serializes the wrapped command into the JSON `command` field, directly returning the password through stdout. 4. The SSH server receives the command as text, potentially exposing it through server ...[truncated 1405 chars]- Remediation
View remediation
