T09 · Insecure Skill Coding Practices
- Location
scripts/utter-join.ts:44- Finding
Shell Command Injection Through Messaging Arguments
- Content
View full analysis
= 0 ? args[channelIdx + 1] : undefined; const targetIdx = args.indexOf("--target"); const target = targetIdx >= 0 ? args[targetIdx + 1] : undefined; ``` ### Technical Analysis `execSync()` receives a single interpolated command string, causing Node.js to execute it through a system shell. The attacker-controlled `channel` value is interpolated without quoting or validation, allowing shell metacharacters such as `;`, `|`, redirection operators, backticks, or `$()` to alter the command. Although `target`, `message`, and `mediaPath` are passed through `JSON.stringify()`, JSON string quoting is not sh ...[truncated 1737 chars]- Remediation
View remediation
