T09 · Insecure Skill Coding Practices
- Location
SKILL.md:84- Finding
Unvalidated Review Scope Can Reach Shell-Oriented Git Commands
- Content
View full analysis
" / "cid " | Single commit | `git show ` | | "review .." | Commit range | `git diff ..` | | "review branch " | Branch vs main/master | `git diff main...` | | "review last N commits" | Recent N commits | `git diff HEAD~N..HEAD` | ``` ### Technical Analysis The Skill directs the agent to extract commit hashes, revision ranges, branch names, and commit counts from user messages and interpolate those values into Git commands. It does not require syntactic validation, reject leading options, use structured argument arrays, or define safe revision boundaries. If `RunCommand` executes the generated command through a shell, shell metacharacters in a crafted scope can introduce additional commands. Even without shell interpretation, values beginning with `-` can be interpreted as Git options and alter the intended operation. This conflicts with the Skill's stated read-only boundary because the command construction process relies on untrusted user input without enforcing that the input is only a valid Git revision. ### Attack Path 1. An attacker asks the Skill to review a commit, range, branch, or number of commits. 2. The attacker places shell syntax or Git options in the user-controlled revision value. 3. The Skill substitutes the value into the documented command template. 4. The agent invokes the resulting command through its `RunCommand` capability. 5. If the command runner uses shell evaluation, injected shell commands execute with the agent process's operatin ...[truncated 1017 chars]- Remediation
View remediation
^{commit}'` through structured arguments. - Reject revisions that fail verification. - Do not permit arbitrary Git options as revision values. 4. **Terminate option parsing where supported** - Use `--` to separate revisions or options from path arguments where appropriate. - Do not rely on `--` as a substitute for validation. 5. **Document the security requirement in `SKILL.md`** - Explicitly prohibit shell interpolation. - Require the agent to reject malformed scope values rather than attempting to repair or execute them. - Restrict `RunCommand` to an allowlist of read-only Git subcommands and approved flags. 6. **Add adversarial evaluation cases** - Test leading-option values, command separators, command substitutions, newlines, malformed ranges, and excessively large commit counts. - Assert that no command is invoked when validation fails. ]]>
