T09 · Insecure Skill Coding Practices
- Location
SKILL.md:38- Finding
Potential Shell Command Injection Through Unsafe Placeholder Substitution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38–69
Vulnerability Type: Shell command injection through insufficiently constrained user input
Risk Level: MediumThe documented operation instructs an agent to invoke an inline Python program and replace
ODDSandTRUE_PROB_PERCENTwith values originating from the user:bash python3 -c " import sys odds_input = sys.argv[1] true_prob = float(sys.argv[2]) / 100 if float(sys.argv[2]) > 1 else float(sys.argv[2]) # Convert to decimal odds if odds_input.startswith('+'): decimal_odds = 1 + int(odds_input) / 100 elif odds_input.startswith('-'): decimal_odds = 1 + 100 / abs(int(odds_input)) elif odds_input.startswith('$') or odds_input.startswith('0.'): price = float(odds_input.replace('$', '')) decimal_odds = 1 / price else: decimal_odds = float(odds_input) implied_prob = 1 / decimal_odds ev_per_dollar = true_prob * decimal_odds - 1 edge = true_prob - implied_prob print(f'Offered odds: {odds_input} (decimal {decimal_odds:.3f})') print(f'Implied probability: {implied_prob:.1%}') print(f'Your true probability: {true_prob:.1%}') print(f'Edge: {edge:+.1%}') print(f'EV per \$1: {ev_per_dollar:+.4f}') print(f'EV per \$100: {ev_per_dollar * 100:+.2f}') print(f'Verdict: {\"✅ +EV — BET\" if ev_per_dollar > 0 else \"❌ -EV — PASS\"} ') " "ODDS" "TRUE_PROB_PERCENT"Technical Analysis
The Python code expects the odds and probability in
sys.argv, but the surrounding skill documentation expresses execution as a shell command containing quoted placeholders. It does not require strict numeric validation before interpolation, a shell-free process API, or shell-safe argument encoding.If an implementing agent performs direct textual replacement of
ODDSorTRUE_PROB_PERCENT, malicious input containing a closing double quote followed by shell syntax can terminate the intended argument. The shell pro ...[truncated 1686 chars]- Remediation
View remediation
Remediation Suggestions
- Move the calculator into a standalone Python script rather than embedding it in a shell command.
- Invoke Python through a structured process API with an argument array and with shell execution disabled. For example, pass
["python3", "calculator.py", odds, probability]directly to the execution tool. - Validate input before execution using strict allowlists:
- Permit American odds only in forms such as
+150or-200. - Permit decimal odds only as a finite positive decimal number.
- Permit Kalshi prices only as numeric values in the valid contract-price range.
- Permit probability only as a finite numeric value in an explicitly documented range.
- Reject quotes, whitespace-separated extra tokens, shell metacharacters, and trailing content.
- Permit American odds only in forms such as
- Perform parsing and range validation inside Python and return a controlled error for zero prices, non-finite values, malformed numbers, and out-of-range probabilities.
- If shell execution is unavoidable, use a platform-appropriate escaping routine for every argument and never interpolate raw user input into executable command text.
- Add regression tests using inputs containing quotes, command separators, substitutions, newlines, and malformed numeric values to verify that none are interpreted by a shell.
