T09 · Insecure Skill Coding Practices
- Location
scripts/grant-access.sh:350- Finding
Remediation Profile Allows Arbitrary Command Execution Through Allowed Interpreters
- Content
View full analysis
/dev/null || printf '%s' "${arg}") local matched=false for prefix in "${allowed_prefixes[@]}"; do if [[ "${resolved}" == "${prefix}"* ]]; then matched=true break fi done if [[ "${matched}" == false ]]; then log_event "BLOCKED" printf 'ERROR: Path '\''%s'\'' outside allowed directories.\n' "${arg}" exit 1 fi fi done } ``` The remediation dispatch profile then permits both remote download tools and general-purpose interpreters: ```bash ALLOWED_READ_PATHS=("/var/log/" "/proc/" "/sys/" "/run/" "/tmp/" "/etc/" "/home/") ALLOWED_WRITE_PATHS=("/etc/" "/var/" "/tmp/" "/home/") dispatch() { local sub case "${COMMAND}" in uptime|hostname|whoami|id|w|uname|df|free|lsblk|mount|ps|kill|pkill|journalctl|dmesg|ss|netstat|lsof|curl|wget) run_cmd ;; dig|nslookup|ping|traceroute|mtr) run_cmd ;; top) if [[ " ${ARGS[*]:-} " == *" -b "* ]] || [[ "${ARGS[0]:-}" == "-bn"* ]]; then run_cmd else log_event "DENIED"; printf 'ERROR: '\''top'\'' requires -b (batch mode).\n'; exit 1 fi ;; cat|head|tail|less|wc|grep|sed|awk|ls) check_paths ALLOWED_READ_PATHS "${ARGS[@]}" run_cmd ;; cp|mv| ...[truncated 2741 chars]- Remediation
View remediation
