T09 · Insecure Skill Coding Practices
- Location
SKILL.md:51- Finding
Shell Command Injection Through Unsafe URL and Title Interpolation
- Content
View full analysis
","title":"optional"}' ``` ### Technical Analysis The documented REST workflow instructs the agent to place a user-provided URL and optional title directly inside a single-quoted shell argument. No structured JSON serialization or shell-safe parameter handling is specified. If an agent constructs this command through textual substitution, a single quote in either user-controlled value can terminate the shell argument. Subsequent shell metacharacters can then be interpreted as commands. Independently, embedded quotation marks, backslashes, or control characters can corrupt the JSON request. For example, a malicious value conceptually shaped as: ```text https://example.invalid/' ; attacker_command ; # ``` could transform the intended `curl` invocation into multiple shell commands if inserted directly into the documented template. The precise payload depends on how the invoking agent performs substitution and whether it validates the URL before command execution. ### Attack Path 1. An attacker asks the agent to shorten a crafted URL or supplies a crafted optional title. 2. The input contains a single quote that closes the `-d` argument, followed by shell syntax and an injected command. 3. The agent follows the Skill's REST instructions and substitutes the untrusted value directly into the command template. 4. The command is passed to a shell. 5. The shell executes the injected command with the same operating-system privileges and environment access as the agent process. This path is applicable when the REST fallback is used and the template is assembled through direct textual ...[truncated 819 chars]- Remediation
View remediation
' TITLE='' jq -n \ --arg url "$URL" \ --arg title "$TITLE" \ '{url: $url, title: $title}' | curl --fail-with-body \ --request POST \ 'https://toui.io/api/v1/shorten' \ --header "Authorization: Bearer $TOUI_API_KEY" \ --header 'Content-Type: application/json' \ --data-binary @- ``` Additional hardening measures: 1. Prefer the structured `shorten_url` MCP tool over shell execution whenever it is available. 2. Validate that the submitted value uses an explicitly permitted scheme, such as `https` or `http`, before sending it. 3. Pass command arguments through a process API without invoking a shell where supported. 4. Never build JSON by concatenating or substituting raw user input. 5. Keep `TOUI_API_KEY` scoped to the minimum required API permissions and prevent it from being logged. 6. Document that URLs and titles are untrusted data and must not be evaluated as shell syntax. ]]>
