T09 · Insecure Skill Coding Practices
- Location
scripts/reddit.mjs:175- Finding
Shell Command Injection During OAuth Browser Launch
- Content
View full analysis
{ // Try to open browser automatically const cmd = process.platform === 'darwin' ? 'open' : process.platform === 'win32' ? 'start' : 'xdg-open'; exec(`${cmd} "${authUrl}"`); }); ``` ### Technical Analysis The OAuth URL incorporates `clientId`, obtained from the `REDDIT_CLIENT_ID` environment variable, without URL encoding. The resulting URL is then interpolated into a command string passed to Node.js `exec`, which invokes a system shell. Double quotes do not prevent all shell evaluation. On Unix-like systems, constructs such as command substitution using `$()` remain active inside double-quoted strings. Consequently, a malicious environment or configuration value can alter the command interpreted by the shell when the user runs the `login` command. The browser launch is legitimate functionality, but using a shell is unnecessary and exceeds the privilege needed merely to open a URL. ### Attack Path 1. An attacker gains the ability to influence the Skill's environment or configuration, including `REDDIT_CLIENT_ID`. 2. The attacker supplies a value containing shell syntax, such as a command-substitution expression. 3. The user or Agent invokes: ```bash node scripts/reddit.mjs login ``` 4. The malicious value is embedded in `authUrl`. 5. `exec` passes the constructed string to the operating-system shell. 6. The shell evaluates the injected syntax and executes the attacker's command with the privileges of the user running the Skill. This path req ...[truncated 624 chars]- Remediation
View remediation
