T09 · Insecure Skill Coding Practices
- Location
minimax-usage.sh:6- Finding
Arbitrary Shell Code Execution Through Unsafe Parent-Directory Environment File Loading
- Content
View full analysis
Vulnerability Details
File Location:
minimax-usage.sh, line 6
Vulnerability Type: Unsafe execution of configuration data
Risk Level: HighVulnerable Code
bash source "$(dirname "$0")/../../.env"Technical Analysis
The Bash
sourcecommand interprets the specified file as shell code in the current process. Consequently, the referenced.envfile is not limited to passiveKEY=VALUEconfiguration entries: it may contain arbitrary commands, command substitutions, redirections, function definitions, or additional script imports.The path also resolves two directories above the script directory. This conflicts with the setup instructions in
SKILL.md, which tell users to create.envin the same directory as the script. The implementation therefore crosses the Skill package boundary and may load an unrelated or less-protected parent configuration file.An attacker who can create or modify the resolved parent
.envcan execute arbitrary commands when a user invokes the Skill. Loading the file occurs before API credential validation, so malicious commands execute regardless of whether the required MiniMax variables are present.Attack Path
-
An attacker obtains write access to the
.envfile located two directories aboveminimax-usage.sh, or causes a crafted project hierarchy to be used. -
The attacker inserts shell commands into that file, for example:
bash MINIMAX_CODING_API_KEY=dummy MINIMAX_GROUP_ID=dummy attacker_command -
A user runs
./minimax-usage.sh. -
Line 6 evaluates the entire
.envfile throughsource. -
attacker_commandexecutes with the same identity, environment, filesystem access, and network permissions as the user running the Skill.
Impact Assessment
Successful exploitation provides arbitrary shell command execution with the invoking user's privileges. The attacker could read or modify files accessible to that ...[truncated 398 chars]
-
- Remediation
View remediation
Remediation Suggestions
-
Resolve configuration relative to the actual script directory and use the location documented in
SKILL.md:bash SCRIPT_DIR="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)" ENV_FILE="${SCRIPT_DIR}/.env" -
Do not use
sourcefor an environment file that may be writable by another party. Parse only the two required keys as data, reject malformed lines, and never evaluate command substitutions or shell expressions. -
Prefer receiving
MINIMAX_CODING_API_KEYandMINIMAX_GROUP_IDfrom an already configured process environment. If file-based configuration is required, use a parser that treats values as literal text. -
Verify that the configuration is a regular file, is not a symbolic link, and is owned by the expected user. Reject files writable by group or other users.
-
Restrict the file permissions because it contains an API credential:
bash chmod 600 .env -
Update
SKILL.mdand the implementation so they specify the same configuration location and security requirements.
-
