T09 · Insecure Skill Coding Practices
- Location
SKILL.md:103- Finding
Shell Command Injection Through Untrusted Place Names
- Content
View full analysis
" --limit 1 --json ``` ``` The same unsafe command construction is repeated for unresolved entries: ```markdown Only re-run resolve for entries that still have `placeId: null` (e.g. manually added entries): ```bash goplaces resolve "" --limit 1 --json ``` ``` Place names can originate from an imported CSV: ```markdown For each non-empty data row (skip the header and blank rows): - `Title` → `name` ``` ### Technical Analysis The Skill instructs the Agent to insert a place name originating from user-supplied CSV data or direct user input into a Bash command. Wrapping the value in double quotes does not make it safe for shell evaluation. Shell substitutions such as `$(command)` and backtick substitutions remain active inside double-quoted strings. An attacker can also attempt to terminate the quoted argument by supplying embedded quotation marks and shell operators. For example, a CSV title containing a value similar to: ```text Restaurant $(touch /tmp/goplaces-injection) ``` could produce: ```bash goplaces resolve "Restaurant $(touch /tmp/goplaces-injection)" --limit 1 --json ``` If the Agent executes the documented command through a shell, the substitution is evaluated before `goplaces` starts. The vulnerability is repeated during initial city classification and later resolution of entries whose place IDs remain unset. The exploitability depends on the Agent's command-execution interface. An API that invokes an executable with a literal argument array would not evaluate shell syntax, but the Skill explicitly presents the operation as a Bash command and does not require such safe invocation. ...[truncated 1434 chars]- Remediation
View remediation
