T09 · Insecure Skill Coding Practices
- Location
scripts/setup-consultant.sh:34- Finding
Unsanitized Template Substitution and Workspace Path Injection
- Content
View full analysis
"$DST" ``` ### Technical Analysis The script places the user-controlled `AGENT_ID`, `DOMAIN`, and derived `WORKSPACE` values directly inside executable `sed` expressions. The values are not escaped for replacement-string metacharacters such as `&` and backslashes, expression delimiters such as `/` and `|`, or embedded newline characters. At minimum, ordinary input containing these characters can corrupt generated files or cause `sed` to terminate with an error. Under GNU `sed`, a crafted value containing expression delimiters and newlines can terminate the intended substitution and introduce an additional command. The GNU `sed` `e` command can execute a shell command, making local command execution possible when untrusted values reach this script. The unvalidated `AGENT_ID` is also incorporated into: ```bash WORKSPACE="$BAS ...[truncated 1794 chars]- Remediation
View remediation
&2 exit 1 fi ``` 2. Canonicalize `BASE` and `WORKSPACE`, then verify that the workspace remains beneath the approved base directory. 3. Reject existing destination directories by default. Require an explicit `--force` option before overwriting files. 4. Do not construct `sed` programs from untrusted values. Use a template renderer that passes replacement values strictly as data. 5. If `sed` must be retained, escape backslashes, ampersands, delimiters, carriage returns, and newlines before substitution. Do not rely on shell quoting alone. 6. Generate files in a private temporary directory created with `mktemp -d`, apply restrictive permissions, validate the output, and move it atomically into place. 7. Add automated tests covering slashes, ampersands, backslashes, newlines, Unicode, traversal strings, and pre-existing destinations. ]]>
