T09 · Insecure Skill Coding Practices
- Location
bilibili_wechat_push.js:76- Finding
Shell Command Injection Through Contact Name and Configurable Script Path
- Content
View full analysis
attacker-command " ``` The precise operators depend on the host shell. The resulting command would be interpreted as multiple shell operations rather than as a single contact argument. The environment-controlled script path presents an additional injection surface ...[truncated 1256 chars]- Remediation
View remediation
