T09 · Insecure Skill Coding Practices
- Location
SKILL.md:34- Finding
Shell Command Injection Through Unsafe Interpolation in Curl Templates
- Content
View full analysis
","use_company_intel":true,"question_count":8}'` - By custom input: - `curl -sS -X POST "http://127.0.0.1:8010/api/interview/prep" -H "Content-Type: application/json" -d '{"company":"MiniAgent","role_title":"AI Agent Intern","jd_text":"Need Python, LangGraph, RAG","use_company_intel":true,"question_count":8}'` ``` ### Technical Analysis The Skill directs an Agent to invoke `curl` through an execution tool while embedding values such as `job_id`, `company`, `role_title`, and `jd_text` inside a single-quoted shell argument. These values originate from user input. If the Agent implements the templates through direct string substitution, a supplied single quote can terminate the JSON argument. The remaining input can then introduce shell metacharacters and an arbitrary command. JSON quoting alone does not provide shell escaping because the shell parses the command before `curl` receives its arguments. The vulnerable pattern is conceptually equivalent to: ```sh curl ... -d '{"job_id":"USER_INPUT", ...}' ``` A malicious value containing a sequence such as: ```text '; attacker_command; # ``` could transform the generated command into multiple shell commands. The issue also applies to free-form JD text, which is particularly likely to contain punctuation and is not constrained or safely serialized by the documented workflow. ### Attack Path 1. An attacker provides a crafted `job_id`, company name, role title, or JD text containing a single quote followed by shell syntax. 2. The Agent follows the documented `exec tool + curl` workflow. 3. The Agent directly substitutes ...[truncated 1401 chars]- Remediation
View remediation
