T09 · Insecure Skill Coding Practices
- Location
scripts/start-tourism-guide.sh:106- Finding
Arbitrary Python Code Execution Through Unsanitized Destination Input
- Content
View full analysis
> "$TASK_FILE" << EOF - 搜索URL: https://www.xiaohongshu.com/search_result?keyword=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))")&type=note&sort=collect_count - 三种排序都要获取: hot / collect_count / time_descending - 正文提取: 必须使用 eval + 提取脚本 agent-browser --cdp 18800 eval "\$(cat $HOME/.openclaw/workspace/skills/xiaohongshu-crawler/scripts/extract-article.js)" --json - 特有问题: 二维码拦截 → 通知用户扫码登录 EOF ;; mafengwo) cat >> "$TASK_FILE" << EOF - 搜索URL: https://www.mafengwo.cn/search/q.php?q=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))")&t=blog - 必须提取浏览量(马蜂窝特有指标) - 特有问题: 目的地页面404 → 改用搜索 EOF ;; ctrip) cat >> "$TASK_FILE" << EOF - 景点页面: https://you.ctrip.com/sight/$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))").html - 游记页面: https://you.ctrip.com/travels/$(python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))").html - 必须提取 ⭐x.x/5 格式评分(携程特有) EOF ;; ``` ### Technical Analysis The destination argument is taken directly from `$1`: ```bash DEST="$1" ``` It is subsequently interpolated into Python source code: ```bash python3 -c "import urllib.parse; print(urllib.parse.quote('$DEST'))" ``` Shell quoting does not make this safe for the Python parser. A destination containing a single quote can terminate the Python string passed to `urllib.parse.quote`, insert additional Python statements, and comment out the remaining syntax. This is a source-code injection vulnerability rather than ordinary URL-encoding failure. The same unsafe construction occurs four times for the Xiaohongshu, Mafengwo, and Ctrip task templates. ### Attack Path 1. An attacker or untrusted caller controls the destination supplied ...[truncated 1340 chars]- Remediation
View remediation
