T09 · Insecure Skill Coding Practices
- Location
SKILL.md:81- Finding
Execution Instructions Reference an Unspecified and Missing Script
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 81-84
Vulnerability Type: Unverified command execution and unsafe argument handling
Risk Level: MediumVulnerable Snippet
The following is an English rendering of the documented commands:
bash # Analyze all open pull requests in a repository bash [refer to the script file in the skill directory] owner/repo --state open --limit 20 # Generate a team dashboard bash [refer to the script file in the skill directory] owner/repo --format dashboard > pr-dashboard.htmlSimilar unspecified command examples appear through line 126.
Technical Analysis
The instructions direct the Agent to execute a Bash script but do not provide its filename or implementation. The audited project contains only
SKILL.md, so there is no local script whose identity, integrity, argument parsing, or behavior can be reviewed.Repository identifiers, labels, author names, and output paths are presented as command-line arguments in related examples. If an Agent attempts to infer the missing command or constructs a shell command by concatenating user-provided values, shell metacharacters could be interpreted as additional commands. Whether exploitation is possible depends on how the absent implementation or Agent handles those parameters; the provided artifact does not implement validation or safe process invocation.
Attack Path
- A user invokes the Skill and supplies a crafted repository identifier or another command parameter.
- The Agent encounters the unspecified script placeholder and guesses, substitutes, or dynamically constructs an executable command.
- The Agent interpolates the supplied value into a shell command without strict validation or argument separation.
- Shell metacharacters in the value may be interpreted as additional commands.
- Those commands execute with the Agent process's permissions and may inherit access to configured GitHub c ...[truncated 466 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the intended script in the project and reference it using an exact, repository-relative path.
- Review and document the script's complete behavior before instructing an Agent to execute it.
- Invoke processes using structured argument arrays rather than concatenated shell strings.
- Validate repository identifiers against a strict format such as
owner/repository. - Apply allowlists and length limits to state, label, author, output-format, and path parameters.
- Reject shell metacharacters and path traversal sequences where they are not legitimate.
- Avoid using
eval,bash -c, or equivalent dynamic shell evaluation. - Run the tool in a restricted environment with minimal filesystem and network permissions.
- Document and enforce the minimum GitHub token scopes required by each operation.
