T09 · Insecure Skill Coding Practices
- Location
SKILL.md:66- Finding
Shell Command Injection Through Unvalidated Node Identifier
- Content
View full analysis
" --duration 1000 --fps 10 --no-audio --out "{skill}/tmp/snap.mp4" \ && ffmpeg -hide_banner -loglevel error -y -ss 00:00:00 -i "{skill}/tmp/snap.mp4" -frames:v 1 "{skill}/tmp/snap.png" ``` ### Technical Analysis The documented workflow places the node identifier directly into a shell command without defining validation or a safe argument-passing mechanism. If an Agent implements this workflow by replacing the `` placeholder with user-controlled text before passing the resulting string to a shell, an attacker can supply shell metacharacters that terminate the quoted argument and introduce additional commands. Double quotes alone do not make textual shell-command construction safe. An input containing a double quote followed by shell operators can escape the intended argument context. The `{skill}` placeholder presents a similar risk if it can be influenced by an untrusted party, although the document appears to treat it as runtime-controlled metadata. ### Attack Path 1. An attacker submits a crafted node identifier through the Skill invocation interface. 2. The Agent substitutes that identifier into the `` placeholder in the documented Bash command. 3. The crafted value closes the quoted `--node` argument and adds shell syntax, for example a value following the pattern `"; attacker-command; #`. 4. The Agent passes the assembled command string to a shell. 5. The shell interprets the injected content as a separate command and executes it with the Agent process's privileges. Successful exploitation depends on the runtime performing textual placeholder substitution and executing the result through a shell. ### Impact Assessment Successful exploitation can provide arbitrary command execution with t ...[truncated 720 chars]- Remediation
View remediation
