T09 · Insecure Skill Coding Practices
- Location
sub-skills/unittest-checker/scripts/analyze-coverage/index.cjs:42- Finding
Shell Command Injection Through Unvalidated Component Names
- Content
View full analysis
&1`, { cwd: projectRoot, encoding: 'utf-8', shell: true, maxBuffer: 50 * 1024 * 1024, }); } ``` The Skill instructions als ...[truncated 1946 chars]- Remediation
View remediation
&1`. Capture `stdout` and `stderr` through process API options. 5. Update the Skill instructions so `$ARGUMENTS` and `$PATH` are never directly interpolated into Bash commands. 6. Add regression tests covering semicolons, spaces, command substitution, pipes, redirections, traversal tokens, control characters, and leading dashes. ]]>
