T09 · Insecure Skill Coding Practices
- Location
skills/parse-qr/SKILL.md:36- Finding
<![CDATA[Shell Command Injection Through Attacker-Controlled Payment Parameters]]>
- Content
View full analysis
" ``` The payment creation instructions similarly interpolate addresses, amounts, and memos: ```bash node scripts/dist/create-payment.js \ --source-chain \ --source-token \ --dest-chain \ --dest-address \ --dest-token \ --dest-amount \ --dest-memo ``` Payment-status lookups also embed user-provided identifiers: ```bash node scripts/dist/get-payment.js --payment-id node scripts/dist/get-payment.js --tx-hash node scripts/dist/get-payment.js --receiver-address --receiver-memo ``` The balance workflow uses the same construction: ```bash node scripts/dist/check-balance.js --address ``` ### Technical Analysis QR payloads, wallet addresses, memos, payment IDs, transaction hashes, and amounts originate from users or external payment requests. The Skill directs the Agent to substitute these values into shell command templates rather than pass them through a non-shell argument-array interface. The JavaScript programs read values from `process.argv`, which is safe only after the process has started. If an Agent constructs and executes the documented command through a shell, shell syntax is interpreted before Node receives the arguments. Quoting QR content with double quotes is insufficient because command substitutions such as `$(...)` and bac ...[truncated 1839 chars]- Remediation
View remediation
