T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
Unsanitized Skill Name Can Reach a Shell Command
- Content
View full analysis
` refers to the resolved skill name. ``` ```bash git -C "${CLAUDE_PROJECT_DIR}" worktree add "${CLAUDE_PROJECT_DIR}/../skills-" -b chore/update- ``` ```markdown Set `` = `${CLAUDE_PROJECT_DIR}/../skills-`. If that path or branch already exists, add the same numeric suffix (`-2`, `-3`, ...) to both the worktree path and the branch name until both are free, and carry that suffix into ``. ``` ### Technical Analysis The skill accepts `$ARGUMENTS` as a skill name and only requires the corresponding `SKILL.md` file to exist. It does not define a strict character allowlist for the resolved value. The resolved `` is subsequently interpolated into a shell command. Although the worktree path is quoted, the branch value in `chore/update-` is not explicitly quoted. If an agent substitutes an attacker-controlled skill directory name containing shell metacharacters, the shell can interpret those characters as command syntax rather than as part of a branch name. Checking that a path exists does not sanitize its name. On file systems that permit shell metacharacters in directory names, an attacker with the ability to add or rename a skill directory could create a name designed to alter the resulting command. ### Attack Path 1. An attacker who can modify the skills repository creates a skill directory whose name includes shell metacharacters. 2. The attacker places a `SKILL.md` file inside that directory, satisfying the d ...[truncated 1201 chars]- Remediation
View remediation
" worktree_path="${CLAUDE_PROJECT_DIR}/../skills-${skill_name}" branch_name="chore/update-${skill_name}" git -C "${CLAUDE_PROJECT_DIR}" worktree add \ "${worktree_path}" \ -b "${branch_name}" ``` 4. Prefer structured process execution in which the executable and argument array are passed separately, rather than constructing a shell command string. 5. Resolve and verify the target path remains under `${CLAUDE_PROJECT_DIR}/skills/` after canonicalization. 6. Repeat validation after adding numeric suffixes, and use `--` where supported to prevent values beginning with a hyphen from being interpreted as options. ]]>
