T09 · Insecure Skill Coding Practices
- Location
scripts/raindrop.sh:11- Finding
Arbitrary Shell Execution Through Executable Credential Configuration
- Content
View full analysis
Vulnerability Details
File Location:
scripts/raindrop.sh, lines 11-13
Vulnerability Type: Unsafe execution of a credential configuration file
Risk Level: Highbash # Auto-source token from config if not set if [[ -z "$TOKEN" && -f ~/.config/raindrop.env ]]; then source ~/.config/raindrop.env fiTechnical Analysis
The script loads
~/.config/raindrop.envwith the Bashsourcebuiltin. Although this file is documented as a credential file,sourceinterprets its entire contents as executable shell code rather than parsing it strictly as data.Consequently, any command, command substitution, function definition, shell redirection, or other Bash construct placed in the file will execute when the CLI starts without an existing
RAINDROP_TOKENenvironment variable. Merely checking that the file exists does not validate its ownership, permissions, type, or contents.Attack Path
- An attacker, compromised process, or malicious installation step gains the ability to create or modify
~/.config/raindrop.env. - The attacker inserts shell commands into the file, for example alongside or instead of the expected token assignment.
- The user invokes any command in
scripts/raindrop.shwithout settingRAINDROP_TOKEN. - The startup logic executes
source ~/.config/raindrop.env. - The attacker-controlled commands execute before the requested Raindrop operation.
Impact Assessment
Successful exploitation provides arbitrary command execution with the privileges of the user or Agent running the Skill. This may permit access to local files and environment secrets, modification or deletion of user data, use of the Raindrop token, network access under the user's identity, and further compromise within that account's permission boundary.
- An attacker, compromised process, or malicious installation step gains the ability to create or modify
- Remediation
View remediation
Remediation Suggestions
Do not execute credential files with
source. Replace this behavior with a non-executing parser that accepts only a single, precisely definedRAINDROP_TOKENassignment.Recommended hardening includes:
- Read the file as plain text rather than Bash code.
- Reject unknown keys, multiline values, command substitutions, and additional statements.
- Confirm that the path is a regular file and not a symbolic link.
- Verify that the file is owned by the current user and is not accessible by group or other users.
- Require mode
0600for the file and mode0700for its containing directory. - Prefer an operating-system credential store or an inherited environment variable where available.
