T09 · Insecure Skill Coding Practices
- Location
SKILL.md:57- Finding
Shell Command Injection Through Unsafe JSON Interpolation
- Content
View full analysis
"}' ``` #### Clarification answer — `SKILL.md:129-131` ```bash curl -s -X POST "$TEAMCLAW_URL/api/v1/clarifications//answer" \ -H "Content-Type: application/json" \ -d '{"answer": "", "answeredBy": "user"}' ``` #### Task creation — `SKILL.md:139-147` ```bash curl -s -X POST "$TEAMCLAW_URL/api/v1/tasks" \ -H "Content-Type: application/json" \ -d '{ "title": "Implement user login", "description": "Create a login form with email/password auth", "priority": "high", "assignedRole": "developer" }' ``` #### Team messaging — `SKILL.md:157-173` ```bash curl -s -X POST "$TEAMCLAW_URL/api/v1/messages/direct" \ -H "Content-Type: application/json" \ -d '{ "from": "user", "toRole": "developer", "content": "Please also add input validation" }' # Broadcast to all workers curl -s -X POST "$TEAMCLAW_URL/api/v1/messages/broadcast" \ -H "Content-Type: application/json" \ -d '{ "from": "user", "content": "Deadline moved up — prioritize core features" }' ``` ### Technical Analysis The skill instructs the agent to insert requirements, clarification answers, task details, and message content into JSON embedded in single-quoted shell arguments. If an implementation performs direct textual substitution, an attacker-controlled single quote can terminate the shell string. Shell operators and commands following that quote may then be interpreted by the local shell. Even where the payload does not achieve ...[truncated 2038 chars]- Remediation
View remediation
