T09 · Insecure Skill Coding Practices
- Location
scripts/bug-hunt.sh:118- Finding
Unsanitized GitHub Issue Titles Enable Indirect Prompt Injection and Terminal Output Manipulation
- Content
View full analysis
/dev/null || echo "[]") ``` ```bash items=$(echo "$EVALUATED" | jq -r --arg cat "$category" ' [.[] | select(.category == $cat)] | map( .dup_of as $d | .quality as $q | (if $d != "" then "🔁 dup of #\($d)" elif $q == "actionable" then "✅ actionable" elif $q == "partial" then "⚡ partial" elif $q == "vague" then "⚠️ vague" else "❓ needs info" end) as $marker | "- #\(.number): \(.title) [\($marker)]" ``` The resulting value is subsequently printed without sanitization: ```bash echo "$items" ``` ### Technical Analysis The script retrieves issue titles from the public `openclaw/openclaw` GitHub repository and includes them verbatim in its report. GitHub issue titles are remotely supplied, attacker-controlled data. The use of `jq -r` converts JSON strings to raw output. Consequently, control characters represented in JSON may be decoded before the title is printed. The script does not remove terminal control sequences, normalize control characters, escape Markdown or prompt-like syntax, or mark issue content as untrusted data. This creates two related attack surfaces: 1. **Indirect prompt injection:** The Skill documentation directs an AI Agent to consume the generated report and use issue information when making an upgrade recommendation. A malicious title can contain instruction-like text intended to alter that analysis. Without a trust boundary, the Agent may interpret data from the issue title as operational instructions rather than as inert evidence. 2. **Terminal output manipulation:** A malicious title containing ...[truncated 2089 chars]- Remediation
View remediation
