T09 · Insecure Skill Coding Practices
- Location
template-filling-execution.md:69- Finding
Unquoted and Unvalidated Shell Parameters in Local Rendering Command
- Content
View full analysis
-d "$VALUES_FILE" -o .docx ``` ``` ### Technical Analysis The local rendering workflow places the template name and output filename into a shell command without showing shell quoting or performing validation at the point of use: - `` is derived from template inventory data, which the project itself identifies as untrusted third-party data. - `` may be influenced by user input. - Unlike `"$VALUES_FILE"`, neither placeholder is shown as a quoted shell argument. - Although `SKILL.md:42-48` defines validation requirements, the linked execution workflow does not apply those requirements before invoking the CLI. If an agent translates these placeholders into raw shell text, shell metacharacters in either value may be interpreted as shell syntax rather than as part of a single argument. Merely documenting validation in another file does not ensure that an agent following this command performs it. ### Attack Path 1. The attacker supplies a crafted output filename, or influences a template name returned by an untrusted template catalog. 2. The value contains shell syntax such as command separators, substitutions, pipes, redirects, or other metacharacters. 3. An agent follows the documented local CLI workflow and directly substitutes that value for `` or ``. 4. The shell parses the injected syntax because the substituted argument is not quoted. 5. The injected command executes under the operating-system account running the agent or CLI. Exploitation depends on the executing agent treating the displayed placeholders as direct shell substitutions without independently applying the separate validation guidance. ### ...[truncated 682 chars]- Remediation
View remediation
&2 exit 1 fi ``` 3. Validate the template name using both an allowlisted character set and inventory membership: ```bash if [[ ! "$TEMPLATE_NAME" =~ ^[A-Za-z0-9_-]+$ ]]; then printf '%s\n' "Invalid template name" >&2 exit 1 fi ``` The workflow must additionally verify that `TEMPLATE_NAME` exactly matches a name in the previously returned template inventory. 4. Do not construct the command through `eval`, `sh -c`, string concatenation, or another shell-parsing layer. 5. Add the validation requirements directly beside the rendering command so the executable workflow does not depend on guidance in a separate file. 6. Add negative tests covering semicolons, command substitutions, whitespace, path separators, redirects, pipes, ampersands, extra filename extensions, and template names absent from the inventory. ]]>
