T09 · Insecure Skill Coding Practices
- Location
SKILL.md:42- Finding
Unsafe JSON Construction Allows Gossip Message Manipulation
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 ;; esac PAYLOAD=$( jq -cn \ --arg type "gossip_push" \ --argjson version "$STATE_VERSION" \ --argjson state "$STATE_DATA" \ --arg sender "$AGENT_ID" \ --argjson timestamp "$(date -u +%s)" \ '{ type: $type, version: $version, state: $state, sender: $sender, timestamp: $timestamp }' ) || exit 1 pilotctl --json send-message "$peer" --data "$PAYLOAD" ``` Additional hardening should include: 1. Validate state against an explicit JSON schema before transmission. 2. Require version and timestamp fields to be bounded non-negative integers. 3. Restrict agent identifiers to an approved format and length. 4. Set maximum payload sizes to prevent resource-exhaustion attacks. 5. Reject payload construction if `jq` fails rather than sending partial or malformed data. 6. Apply the same correction to both command examples in the file. ]]>
