T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_tables.py:208- Finding
Arbitrary Command Execution Through Unsafe Shell Command Construction
- Content
View full analysis
"{tmp_file}" 2>&1' result = subprocess.run(cmd_redirect, shell=True, timeout=30) ``` A second vulnerable command-construction path handles paginated records: ```python if cursor: cmd = (f'mcporter --config {config_path} call dingtalk-ai-table.search_base_record ' f'dentryUuid="{doc_id}" sheetIdOrName="{sheet_identifier}" ' f'limit={page_limit} cursor="{cursor}" > "{tmp_file}" 2>&1') else: cmd = (f'mcporter --config {config_path} call dingtalk-ai-table.search_base_record ' f'dentryUuid="{doc_id}" sheetIdOrName="{sheet_identifier}" ' f'limit={page_limit} > "{tmp_file}" 2>&1') subprocess.run(cmd, shell=True, timeout=30) ``` ### Technical Analysis The code constructs command strings by interpolating configuration paths, user-supplied keywords, document identifiers, sheet identifiers, and pagination cursors. These strings are then executed using `shell=True`. Wrapping a value in double quotes does not make it safe for shell execution. A malicious value can terminate the quoted argument or invoke shell substitutions. Relevant input sources include: - The `--keyword` command-line argument. - `DINGTALK_MCP_CONFIG`, which controls `config_path`. - Document and sheet identifiers returned by the MCP service. - Paginat ...[truncated 1332 chars]- Remediation
View remediation
