T09 · Insecure Skill Coding Practices
- Location
scripts/resolve_dosbox.py:33- Finding
Shell Command Injection in Generated DOSBox Launch Commands
- Content
View full analysis
str: return '"' + value.replace('"', '\\"') + '"' def build_folder_command(binary: str, game_path: Path) -> str: return ( f"{quote(binary)} " f"-c \"mount c {game_path}\" " f"-c \"c:\" " f"-c \"dir\"" ) def build_iso_command(binary: str, game_path: Path | None, iso_path: Path) -> str: parts = [quote(binary)] if game_path: parts.append(f'-c "mount c {game_path}"') parts.append(f'-c "imgmount d {iso_path} -t iso"') if game_path: parts.append('-c "c:"') else: parts.append('-c "d:"') parts.append('-c "dir"') return " ".join(parts) ``` ### Technical Analysis The command-building functions interpolate `game_path` and `iso_path` directly into shell-ready command strings. These paths are placed inside nested double-quoted arguments without escaping embedded quotes, shell metacharacters, command separators, or control characters. The `quote()` function is only applied to the detected DOSBox binary, not to either user-controlled path. Furthermore, replacing a quote with `\"` is not a portable command-line serialization strategy because escaping rules differ between POSIX shells, Windows `cmd.exe`, and PowerShell. The script only prints these commands and does not execute them itself. Exploitation therefore requires a user or an Agent to copy or execute the generated command. This is nevertheless a meaningful trust-boundary issue because the Skill explicitly presents the output as a launch command suitable for use. ### Attack Path 1. An attacker supplies a game directory or ISO whose path contains a quote followed by shell syntax. 2. A user or Agent invokes `resolve_dosbox.py` with that path. ...[truncated 1064 chars]- Remediation
View remediation
