T09 · Insecure Skill Coding Practices
- Location
SKILL.md:36- Finding
Shell Command Injection Through Unsafely Interpolated Meeting Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 36-38
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable Code:
bash python3 .claude/skills/feishu-doc/scripts/doc_ctl.py create "会议纪要 - {title} - {date}" --content "{minutes_content}"Technical Analysis
The documented command directly interpolates the meeting title, date, and generated minutes into a shell command. These values can contain user-controlled meeting content.
Wrapping values in double quotes does not make shell interpolation safe. Shell constructs such as command substitutions remain active inside double quotes, while embedded quotation marks can terminate an argument and introduce additional shell syntax. For example, an attacker could place a command-substitution expression in a meeting title or include a quotation mark followed by a command separator in the meeting content.
If the agent constructs and executes this command through a shell, the malicious content is interpreted as shell syntax rather than being passed exclusively as data to
doc_ctl.py.Attack Path
- An attacker asks the skill to create meeting minutes and supplies a crafted title, date, or discussion content containing shell metacharacters or command substitution syntax.
- The skill fills the corresponding
{title},{date}, or{minutes_content}placeholder with that attacker-controlled value. - The agent follows the Feishu synchronization instruction and executes the resulting command through a shell.
- The shell evaluates the injected syntax before or alongside the intended Python process.
- The attacker's command executes with the same operating-system identity and permissions as the agent process.
Exploitation depends on the agent executing the documented command through a shell and on attacker-controlled text reaching the placeholders without robust shell escaping.
Impact Assessment
Successful exploitati ...[truncated 713 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not construct a shell command by concatenating or interpolating meeting data.
- Invoke the Python script with an argument-array API that bypasses shell parsing, such as Python
subprocess.run([...], shell=False, check=True). - Prefer passing the potentially large minutes content through standard input or a dedicated API instead of a command-line argument.
- If a temporary file is required, create it with restrictive permissions, use a trusted temporary-file API, and delete it after use.
- Treat the title, date, and all generated meeting content as untrusted data. Apply validation and reasonable length limits before sending them to external services.
- Do not rely solely on quote replacement or ad hoc escaping. If shell execution is unavoidable, use a well-tested platform-specific escaping mechanism for every dynamic argument.
- Add security tests using embedded quotation marks, command separators, backticks, dollar-sign command substitutions, newlines, and other shell metacharacters to verify that supplied content is always handled as literal data.
