T09 · Insecure Skill Coding Practices
Warning
- Location
SKILL.md:62- Finding
Untrusted AGENT Value Injected into jq Expressions
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 fi TOTAL=$(pilotctl --json task list | jq --arg agent "$AGENT" '[.[] | select(.target == $agent)] | length') SUCCESSFUL=$(pilotctl --json task list | jq --arg agent "$AGENT" '[.[] | select(.target == $agent and .status == "completed")] | length') ``` Apply the following additional hardening: 1. Validate `AGENT` against the identifier format accepted by `pilotctl`. 2. Check the exit status of both `pilotctl` and jq before using their results. 3. Confirm that `TOTAL` is numeric and greater than zero before division to prevent invalid success-rate calculations. 4. Apply the same `jq --arg` pattern to `TASK_ID` in the workflow example rather than embedding it into jq program text. 5. Ensure SLA enforcement decisions fail safely when task data cannot be retrieved or parsed. ]]>
