T09 · Insecure Skill Coding Practices
- Location
SKILL.md:48- Finding
Shell Command Injection Through Unsafely Interpolated MCP Arguments
- Content
View full analysis
--message ""` - `pilot_send_message`: Run `pilotctl --json send-message --data ""` - `pilot_recv`: Run `pilotctl --json recv ` - `pilot_listen`: Run `pilotctl --json listen ` Discovery: - `pilot_find`: Run `pilotctl --json find ` - `pilot_lookup`: Run `pilotctl --json lookup ` Pub/Sub: - `pilot_publish`: Run `pilotctl --json publish --data ""` - `pilot_subscribe`: Run `pilotctl --json subscribe ` Gateway: - `pilot_gateway_start`: Run `pilotctl --json gateway start` - `pilot_gateway_map`: Run `pilotctl --json gateway map ` ``` ### Technical Analysis The skill blueprint places MCP tool arguments directly into command-line templates without requiring validation, escaping, or shell-free process execution. Arguments such as `target`, `port`, `msg`, `hostname`, `topic`, `node_id`, and `local-ip` may therefore cross an unsafe boundary from an MCP caller into a command shell. Quoting message values with double quotes is not sufficient protection. POSIX-compatible shells still evaluate command substitution such as `$(...)` and backticks inside double-quoted strings. Unquoted parameters can additionally introduce separators, redirections, pipelines, substitutions, or extra command-line arguments. The project does not contain the referenced `mcp_pilot_server.py`, so direct exploitation cannot be verified against an implementation. Nevertheless, implementing the documented templates using shell command strings would create a command-injection vulnerability. ### Attack Path 1. An attacker obtains access to one of the exposed MCP tools or causes an agent to invoke it with attacker-controlled data. 2. The attacker ...[truncated 1058 chars]- Remediation
View remediation
