T09 · Insecure Skill Coding Practices
- Location
SKILL.md:91- Finding
Shell Command Injection Through Dynamically Interpolated Notebook and Tweet Content
- Content
View full analysis
\"" } ``` For each folder with a resolved notebook, push each bookmark as a text source (X URLs can't be scraped by NotebookLM): ```json { "tool": "exec", "command": "mcporter call notebooklm.source_add notebook_id=\"\" source_type=text text=\"@author: tweet text\n\nSource: https://x.com/author/status/id\"" } ``` ``` ### Technical Analysis The Skill instructs the Agent to construct executable command strings by interpolating dynamic values into shell commands. The affected values include: - A user-supplied notebook title. - Notebook identifiers returned by another tool. - Tweet author names and tweet text retrieved from X. - Tweet URLs generated from externally sourced account and status data. Wrapping these values in double quotes is not sufficient shell escaping. Shell constructs such as `$(command)` and backticks remain active inside double-quoted strings, while embedded quotation marks can terminate the intended argument and introduce additional shell syntax. Consequently, a malicious notebook title or bookmarked tweet could modify the command executed by the Agent if the `exec` facility passes the documented command string to a shell. This issue applies to the agent-directed workflow in `SKILL.md`. The separate `scripts/auto_sync.py` implementation uses an argument-vector subprocess call without `shell=True` and therefore does not expose the same shell injection sink. ### Attack Path 1. An attacker publishes an X post containing shell syntax, such as command substitution or a quotation mark followed by additional shell commands. 2. The victim bookmarks the post. 3. The victim invokes ...[truncated 1242 chars]- Remediation
View remediation
