T09 · Insecure Skill Coding Practices
- Location
baidu_scholar_search.sh:13- Finding
Unescaped User Input Allows JSON Request-Body Injection
- Content
View full analysis
Vulnerability Details
File Location:
baidu_scholar_search.sh, lines 13–25
Vulnerability Type: JSON injection through unsafe string interpolation
Risk Level: Mediumbash WD="$1" if [ -z "$WD" ]; then echo '{"error": "Missing wd parameter"}' exit 1 fi pageNum="${2:-0}" enable_abstract="${3:-false}" curl -s -X POST \ -H "Authorization: Bearer $SKILLBOSS_API_KEY" \ -H "Content-Type: application/json" \ -d "{\"type\": \"search\", \"inputs\": {\"query\": \"$WD\"}, \"prefer\": \"balanced\"}" \ "https://api.skillboss.co/v1/pilot"Technical Analysis
The script places the attacker-controlled
WDargument directly inside a manually constructed JSON string. It does not encode JSON metacharacters such as quotation marks, backslashes, or control characters.An input containing JSON syntax can therefore terminate the intended
querystring and add properties to the request. For example, an argument shaped like:text x","additional_property":"attacker-controlledcauses the
inputsobject sent to the remote API to contain an injected property:json { "type": "search", "inputs": { "query": "x", "additional_property": "attacker-controlled" }, "prefer": "balanced" }More complex payloads could close nested objects and introduce duplicate or unexpected top-level fields. The resulting behavior depends on the remote API's schema validation and duplicate-key handling. Inputs containing ordinary quotation marks or backslashes can also produce malformed JSON and cause a denial of service for the individual request.
This is JSON injection, not shell command injection:
WDremains within a shell-quoted argument, so shell metacharacters embedded in it are not evaluated as commands.Attack Path
- An attacker or untrusted caller supplies a crafted search keyword containing quotation marks and JSON syntax.
- The script as ...[truncated 1081 chars]
- Remediation
View remediation
Remediation Suggestions
Construct the request body with a JSON-aware serializer rather than manual interpolation. For example, using
jq:bash payload="$( jq -n --arg query "$WD" \ '{type: "search", inputs: {query: $query}, prefer: "balanced"}' )" curl --fail-with-body --silent --show-error -X POST \ -H "Authorization: Bearer $SKILLBOSS_API_KEY" \ -H "Content-Type: application/json" \ --data-binary "$payload" \ "https://api.skillboss.co/v1/pilot"If
jqis used, declare it as a required executable in the Skill metadata. Alternatively, use another available JSON library that guarantees correct string escaping.Additional hardening should include:
- Rejecting search terms containing disallowed control characters or exceeding a reasonable length.
- Enabling
curl --fail-with-body --show-errorso transport and HTTP failures are visible. - Validating that the generated payload is valid JSON before transmission.
- Adding regression tests for quotation marks, backslashes, newlines, Unicode text, and attempted structural JSON injection.
- Either implementing and validating
pageNumandenable_abstractor removing those currently unused arguments to prevent misleading behavior.
