T09 · Insecure Skill Coding Practices
- Location
<state_id>`, or - `terraform_runtime_online.sh apply <file> --state-id <state_id>`. 2. The script appends the value to `aliyun_cmd` without shell-safe quoting. 3. `eval "$aliyun_cmd"` reparses the attacker-controlled shell syntax. 4. The injected command executes locally with the same operating-system privileges and environment as the Skill process. 5. The injected process may read local Aliyun credentials, modify files, invoke network tools, or execute further cloud commands. ### Impact Assessment Suc ...[truncated 699 chars]:164- Finding
Shell Command Injection Through Unquoted State IDs and eval
- Content
View full analysis
&2 [[ -n "$state_id" ]] && echo "Using existing state: $state_id" >&2 token="$(uuidgen)" aliyun_cmd="aliyun iacservice execute-terraform-plan --endpoint $ENDPOINT --client-token $token --code \"\$code\"" [[ -n "$state_id" ]] && aliyun_cmd="$aliyun_cmd --state-id $state_id" response=$(eval "$aliyun_cmd" 2>&1) || { echo "$(_red)Error: execute-terraform-plan failed$(_reset)" >&2; echo "$response" >&2; exit 1; } ``` The apply path repeats the same construction pattern: ```bash local token aliyun_cmd response new_state_id local max_retries=6 retry_delay=10 retry=0 token="$(uuidgen)" _build_cmd() { local cmd="aliyun iacservice execute-terraform-apply --endpoint $ENDPOINT --client-token $token" [[ -n "$code" ]] && cmd="$cmd --code \"\$code\"" [[ -n "$state_id" ]] && cmd="$cmd --state-id $state_id" echo "$cmd" } aliyun_cmd=$(_build_cmd) while true; do response=$(eval "$aliyun_cmd" 2>&1) && break ``` ### Technical Analysis The script constructs a shell command as a string, appends the caller-supplied `state_id` without quoting or format validation, and executes the result with `eval`. `eval` causes shell syntax contained in `state_id` to be parsed a second time. Consequently, shell metacharacters such as command separators, substitutions, or redirections can alter the intended command and introduce arbitrary local commands. Although legitimate state IDs originate from Alibaba Cloud, the script also accepts state IDs directly from command-line arguments. The code does not establish that the value came from a trusted service response. ### Attack Path ...[truncated 1200 chars]- Remediation
View remediation
&1) || { echo "$(_red)Error: execute-terraform-plan failed$(_reset)" >&2 echo "$response" >&2 exit 1 } ``` 3. Apply the same array-based construction to `execute-terraform-apply`. 4. Validate state IDs against the exact format documented by IaCService before using them. 5. Reject values containing whitespace or shell metacharacters if the service format does not require them. 6. Add regression tests using state IDs containing semicolons, substitutions, quotes, spaces, and redirections, verifying that none can cause a second command to run. ]]>
