T09 · Insecure Skill Coding Practices
- Location
SKILL.md:34- Finding
Shell Command Injection Through Unvalidated URL Placeholder Substitution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s odds-comparison purpose is coherent, but its instructions tell agents to insert user-controlled values directly into shell and Python commands, which creates a real code-execution risk.
Review before installing. The skill is not deceptive and does not install persistent code, but use it only if your agent will treat all event names, categories, tickers, platform names, and odds values as untrusted data and rewrite the examples to pass values via URL encoding, argv, stdin, or JSON instead of interpolating them into commands.
SKILL.md:34Shell Command Injection Through Unvalidated URL Placeholder Substitution
SKILL.md:111Python Code Injection in Generated Cross-Market Comparison Script
SKILL.md:160Python Code Injection in Quick Odds Conversion Template
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
Replace INPUT_VALUE with the user's value (e.g., "-150", "0.62", "$0.58").
## Output Rules
1. Always show implied probability as the primary format (3 decimal places, e.g., 0.620)
2. Include American odds equivalent alongside probability for sportsbook-familiar users
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Pull American odds from The Odds API and convert to implied probability inline:
curl -s "https://api.the-odds-api.com/v4/sports/SPORT_KEY/odds?apiKey=$ODDS_API_KEY®ions=us&markets=h2h&oddsFormat=american" \
| jq '[.[] | {
event: "\(.away_team) vs \(.home_team)",
start: .commence_time,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Pull contract prices from Kalshi's public market data API:
curl -s "https://api.elections.kalshi.com/trade-api/v2/markets?status=open&limit=10&series_ticker=SERIES_TICKER" \
| jq '[.markets[] | {
event: .title,
source: "kalshi",
No suspicious patterns detected.