T09 · Insecure Skill Coding Practices
- Location
SKILL.md:44- Finding
Shell Command Injection Through User-Controlled Query Interpolation
- Content
View full analysis
/tmp/multisage-output.txt 2>&1 cat /tmp/multisage-output.txt # Wrong — tee can cause issues in non-TTY contexts multisage -q "your question" | tee output.txt # DON'T DO THIS ``` Equivalent unsafe interpolation patterns also appear at `SKILL.md:58-61` and `SKILL.md:108-124`. ### Technical Analysis The Skill instructs the Agent to place a user-provided question directly inside a double-quoted shell command. Shell double quotes do not prevent command substitution through constructs such as `$(command)` or backticks. If the Agent textually replaces `"your question"` with untrusted content, the shell evaluates command substitutions before invoking `multisage`. Embedded quotes or other shell syntax can also terminate or alter the intended argument. The documentation supplies no argument-array invocation, strict escaping procedure, or other mechanism that reliably separates user data from shell syntax. For example, a question containing `$(id)` could cause `id` to execute locally while its output is inserted into the argument sent to `multisage`. ### Attack Path 1. An attacker asks the Agent to consult Multisage about a question containing shell command-substitution syntax. 2. The Agent follows the Skill and inserts the question into the documented Bash command. 3. Bash parses the resulting command and evaluates the attacker-controlled substitution. 4. The injected command executes with the operating-system permissions of the Agent process. 5. The attacker may use the execution primitive to read accessible files, modify workspace data, invoke network tools, or launch additional payloads. ### Impact Assessment Successful exploitation provides arbitrary command execution with the privileges of the user running the Agent. The affecte ...[truncated 207 chars]- Remediation
View remediation
