T09 · Insecure Skill Coding Practices
- Location
SKILL.md:118- Finding
Shell Command Injection Through Unvalidated Triage Parameters
- Content
View full analysis
--search-root "$HOME/secopsai" --json ``` ```bash secopsai triage close --disposition --note "" --json ``` ### Technical Analysis The command templates place chat-derived values directly into shell commands. `` and `` are unquoted, while `` is enclosed only in double quotes. The skill does not require strict format validation, allowlisting, or shell-safe argument handling before executing these commands. An attacker can inject shell metacharacters through an unquoted finding ID or disposition. The quoted note is also unsafe because an attacker can terminate the quoted string with `"` or use command substitution such as `$(...)`, which remains active inside double quotes. The confirmation requirement for closing findings reduces accidental execution but does not neutralize malicious syntax in a confirmed value. The investigation workflow is read-only at the application level and does not require confirmation, but shell injection could turn it into an arbitrary write or execution operation. ### Attack Path 1. An attacker supplies a crafted finding identifier, disposition, or analyst note through chat or other content processed as a user request. 2. The agent substitutes the supplied value into the documented shell command. 3. The command is passed to a shell through the agent's execution tool. 4. Shell metacharacters, quote termination, or command substitution are interpreted before `secopsai` processes its arguments. 5. The injected command runs with the operating-system permissions and environment of the OpenClaw agent. For example, an unquoted finding identifier containing a command separator could append another comma ...[truncated 705 chars]- Remediation
View remediation
