T09 · Insecure Skill Coding Practices
- Location
SKILL.md:44- Finding
Shell Command Injection Through Direct Query Interpolation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 44-53
Vulnerability Type: Shell command injection
Risk Level: HighRelevant code snippet:
json { "tool": "exec", "command": "python3 scripts/analyze.py --query \"<user query>\"", "yieldMs": 150000, "timeout": 300, "background": false }The placeholder above is the English rendering of the user-query placeholder in the source instruction.
Technical Analysis
The Skill instructs the agent to insert a user-derived query directly into a command string delimited by double quotes. If the
execimplementation passes this string through a command shell, an attacker can include a double quote followed by shell operators to terminate the intended argument and append arbitrary commands.Argument parsing in
scripts/analyze.pydoes not prevent this vulnerability. Shell metacharacters are interpreted before Python starts and beforeargparsereceives the resulting arguments.The vulnerable data flow is:
- An untrusted user supplies the market-analysis query.
- The agent interpolates that query into the documented command template.
- The
exectool submits the resulting command string to a shell. - Shell syntax embedded in the query may be interpreted as additional commands.
Attack Path
- An attacker submits a query containing a closing double quote, shell separator, command, and comment marker, following the conceptual pattern:
text benign text"; attacker-command; # - The agent substitutes the complete query into the required
commandfield. - The closing quote terminates the
--queryvalue. - The shell separator starts an additional attacker-selected command.
- The comment marker suppresses the trailing quote or other remaining command text.
- The injected command executes under the same operating-system identity and permissions as the agent or
execprocess.
...[truncated 750 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not construct shell command strings using direct interpolation of user-controlled input.
- Invoke the program with an argument array and disable shell processing. The logical invocation should be equivalent to:
python ["python3", "scripts/analyze.py", "--query", query] - If the execution interface accepts only command strings, change the interface or transfer the query through a safely generated input file or standard input.
- Do not rely on manual replacement, simple quote escaping, regular expressions, or a metacharacter blacklist as the primary defense.
- Apply input length limits and reject control characters as defense-in-depth measures.
- Run the script under a restricted account with minimal filesystem and network permissions.
- Add automated tests using quotes, command separators, command substitutions, newlines, and redirection operators to verify that query content is always handled as one literal argument.
