T09 · Insecure Skill Coding Practices
- Location
register.sh:84- Finding
Arbitrary Python Code Execution Through Unsafely Interpolated Agent Slug
- Content
View full analysis
Vulnerability Details
File Location:
register.sh:84-99,deregister.sh:63-77,heartbeat.sh:62-76, andstatus.sh:81-111
Vulnerability Type: Python source-code injection
Risk Level: HighVulnerable Code
The same vulnerable construction appears in multiple scripts. For example,
register.shcontains:bash EXISTING_ID=$(echo "$EXISTING_BODY" | python3 -c " import sys, json slug = '$AGENT_SLUG_VAL' try: data = json.load(sys.stdin) agents = data.get('data', data) if isinstance(data, dict) else data if isinstance(agents, list): for a in agents: if a.get('slug') == slug: print(a.get('id', '')) break except: pass " 2>/dev/null)Equivalent direct interpolation occurs in:
bash AGENT_ID=$(echo "$EXISTING" | python3 -c " import sys, json slug = '$AGENT_SLUG_VAL' try: data = json.load(sys.stdin) agents = data.get('data', data) if isinstance(data, dict) else data if isinstance(agents, list): for a in agents: if a.get('slug') == slug: print(a.get('id', '')) break except: pass " 2>/dev/null)Technical Analysis
AGENT_SLUG_VALcan originate from a command-line--slugargument, theAGENT_SLUGenvironment variable, or the sourceda2a.conffile. The scripts insert that value directly into the source passed topython3 -c.Shell quoting does not make this safe because the attacker-controlled value becomes part of the generated Python program. A value containing a single quote, Python statement separators, and additional Python expressions can terminate the intended string assignment and inject new statements. Python then executes those statements with the privileges of the user running the Skill.
The broad
exceptblocks do not mitigate this issue. Injected statements are evaluated while Python parses and executes the ...[truncated 1126 chars]- Remediation
View remediation
Remediation Suggestions
Never interpolate configuration or argument values into Python source. Pass the slug as a positional argument:
bash EXISTING_ID=$(printf '%s' "$EXISTING_BODY" | python3 -c ' import sys, json slug = sys.argv[1] try: data = json.load(sys.stdin) agents = data.get("data", data) if isinstance(data, dict) else data if isinstance(agents, list): for agent in agents: if agent.get("slug") == slug: print(agent.get("id", "")) break except (json.JSONDecodeError, TypeError, AttributeError): pass ' "$AGENT_SLUG_VAL")Apply the same correction to
deregister.sh,heartbeat.sh, andstatus.sh. Additionally:- Validate slugs against an explicit allowlist, such as
^[a-z0-9][a-z0-9-]{0,62}$. - Reject control characters, quotes, whitespace, and unexpected punctuation.
- Avoid broad exception suppression and report parsing failures safely.
- Add regression tests using slugs containing quotes, newlines, semicolons, and Unicode edge cases.
- Validate slugs against an explicit allowlist, such as
