T09 · Insecure Skill Coding Practices
- Location
SKILL.md:35- Finding
Command Injection Through Unsafe Shell Interpolation
- Content
View full analysis
" ``` `references/feishu-sync.md:6`: ```bash python3 .claude/skills/feishu-doc/scripts/doc_ctl.py create "会议纪要 - {{title}} - {{date}}" --content "" ``` `references/feishu-sync.md:12`: ```bash python3 .claude/skills/feishu-doc/scripts/doc_ctl.py append "追加内容" ``` `references/feishu-sync.md:18`: ```bash python3 .claude/skills/feishu-doc/scripts/doc_ctl.py replace --section "决议事项" "## 决议事项\n新内容" ``` ### Technical Analysis The documented workflow places dynamic meeting titles, dates, rendered Markdown, document identifiers, and replacement or appended content directly into shell command strings. These values can originate from untrusted meeting notes, transcripts, or direct user input. If the agent constructs and executes the examples through a shell, an attacker can terminate the intended quoted argument or use shell evaluation features such as command substitution. Double quotes do not prevent constructs such as `$(command)` from being evaluated. Unquoted placeholders such as `` are additionally exposed to shell metacharacter interpretation and argument injection. Quoting alone is not a reliable fix because shell evaluation rules are complex and meeting content can contain arbitrary Markdown, quotation marks, substitutions, and line breaks. The implementation of the referenced `doc_ctl.py` script is not included in the audited project. Consequently, this finding concerns the unsafe command-construction instructions in the supplied skill rather ...[truncated 1511 chars]- Remediation
View remediation
