T09 · Insecure Skill Coding Practices
- Location
SKILL.md:57- Finding
Shell Command Injection Through Unsafely Interpolated Idea Pitch
- Content
View full analysis
\" depth=quick" } ``` ``` ### Technical Analysis The skill instructs the agent to insert the generated `` value directly into a command executed through the `exec` tool. The pitch is derived from user input and information obtained from untrusted websites, including Reddit, Hacker News, and GitHub. Wrapping the value in double quotes does not make it safe for shell execution. Shell constructs such as command substitution—`$(command)` or backticks—are still evaluated inside double-quoted strings. An embedded quotation mark could also terminate the intended argument and introduce additional shell operators or commands. For example, if the resulting pitch contains: ```text Useful project $(touch /tmp/idea-spark-injected) ``` the constructed command becomes: ```bash mcporter call idea-reality.idea_check idea_text="Useful project $(touch /tmp/idea-spark-injected)" depth=quick ``` A shell would execute `touch /tmp/idea-spark-injected` before invoking `mcporter`. More harmful commands could be substituted in the same way. Exploitation requires the optional validation workflow to be available and invoked, and the attacker-controlled shell syntax must survive the idea-synthesis step. Nevertheless, the documented command construction establishes an unsafe path from untrusted content to shell execution. ### Attack Path 1. An attacker supplies a domain, request, or other input containing shell command-substitution syntax, or publishes crafted content likely to appear in one of the configured web searches. 2. The skill searches external websites and generates a project pitch from user-controlled or remotely controlled content. 3. The generat ...[truncated 1235 chars]- Remediation
View remediation
- depth=quick ``` The runtime must pass these arguments directly to the process without invoking a shell. 2. **Prefer a structured tool call.** If `idea-reality.idea_check` is available as an MCP tool, call it directly using structured JSON rather than routing it through `exec`. 3. **Treat generated content as untrusted.** Apply the same security controls to model-generated pitches as to direct user input because pitches incorporate untrusted user and web content. 4. **Do not rely only on double quotes or character removal.** Generic filtering is error-prone across shells and platforms. If shell execution is unavoidable, use a platform-specific, well-tested argument-escaping library and reject unexpected control characters, newlines, and shell metacharacters as defense in depth. 5. **Run validation with least privilege.** Restrict filesystem, environment-variable, credential, and network access available to the validation process so that any residual command-execution flaw has limited impact. 6. **Add adversarial tests.** Verify that pitches containing payloads such as `$(id)`, backticks, quotes, semicolons, newlines, redirections, and logical operators are passed as literal data and are never interpreted by a shell. ]]>
