T09 · Insecure Skill Coding Practices
- Location
SKILL.md:76- Finding
Shell Command Injection Through Unsanitized Company Name Interpolation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 76-127
Vulnerability Type: Shell command injection through unsafe interpolation of user-controlled input
Risk Level: HighEvidence
bash # 1. Core corporate information agent-browser open "https://www.baidu.com/s?wd={company}+参保人数+高新技术企业" agent-browser snapshot -c # 2. Shareholders, affiliated companies, and branches agent-browser open "https://www.baidu.com/s?wd={company}+股东+实际控制人+分支机构" agent-browser snapshot -c # 3. Official website and business information agent-browser open "https://www.baidu.com/s?wd={company}+官网" agent-browser snapshot -c # 4. Financing information agent-browser open "https://www.baidu.com/s?wd={company}+融资" agent-browser snapshot -c # 5. Recruitment activity agent-browser open "https://www.baidu.com/s?wd={company}+招聘+最新" agent-browser snapshot -c # 6. Bid awards agent-browser open "https://www.baidu.com/s?wd={company}+中标+2024+2025" agent-browser snapshot -c # 7. Recent news agent-browser open "https://so.toutiao.com/search?keyword={company}" agent-browser snapshot -c # 8. WeChat articles agent-browser open "https://wx.sogou.com/weixin?type=2&query={company}" agent-browser snapshot -c # 9. Executive background agent-browser open "https://www.baidu.com/s?wd={company}+创始人+董事长+经历" agent-browser snapshot -c # 10. Local activities agent-browser open "https://www.baidu.com/s?wd={company}+苏州+工业园区" agent-browser snapshot -c # 11. Cooperation projects agent-browser open "https://www.baidu.com/s?wd={company}+战略合作+签约" agent-browser snapshot -c # 12. Supplemental verification agent-browser open "https://www.so.com/s?q={company}+核心业务+产品优势" agent-browser snapshot -cTechnical Analysis
The
{company}placeholder represents a company name supplied by the user. It is inserted directly into double-quoted shell command arguments without URL encoding, strict character va ...[truncated 1942 chars]- Remediation
View remediation
Remediation Suggestions
- Do not construct shell commands by inserting raw user input into command strings.
- Validate company names against a narrowly defined policy. Reject control characters, quotes, newlines, backticks, dollar signs, redirection characters, and shell control operators.
- URL-encode the company name using a fixed, trusted encoding function before constructing the search URL.
- Pass the command and its arguments through a direct process-spawning API that does not invoke a shell.
- If Bash is unavoidable, place the encoded URL in a safely quoted positional parameter rather than generating executable command text.
- Configure the tool authorization layer to reject compound commands, substitutions, pipes, redirections, newlines, and additional executables even when the command starts with
agent-browser. - Add tests using adversarial input containing quotes, semicolons, command substitutions, newlines, and URL delimiters to verify that it remains a single inert URL argument.
