T09 · Insecure Skill Coding Practices
- Location
SKILL.md:59- Finding
Shell Command Injection Through Unescaped Prompt, Output Path, and Proxy Values
- Content
View full analysis
/images/img_name.jpg" ``` The proxy workflow similarly instructs the Agent to interpolate a user-provided proxy value: ```bash HTTPS_PROXY="" HTTP_PROXY="" node /path/to/skills/snap-illustrator/scripts/generate.mjs --prompt "..." --output "..." ``` The surrounding instructions direct the Agent to persist and reuse the supplied value: ```yaml metadata: openclaw: requires: env: - HF_TOKEN bins: - node http_proxy: "http://127.0.0.1:7890" ``` ```bash HTTPS_PROXY="" HTTP_PROXY="" node /path/to/skills/snap-illustrator/scripts/generate.mjs --prompt "..." --output "..." ``` ### Technical Analysis The Skill instructs the Agent to construct a shell command by interpolating three values that are not guaranteed to be trusted: 1. An image prompt derived from user-controlled Markdown content. 2. An output path derived from the user's workspace. 3. A proxy URL supplied directly by the user. Placing these values inside double quotes does not make them safe for shell execution. POSIX-compatible shells still evaluate command substitution expressions such as `$(command)` and backticks inside double-quoted strings. Embedded quotation marks can also terminate the intended argument and introduce shell operators or additional commands. The Node.js script itself parses an argument array and does not require shell interpretation. Consequently, invoking it through a command string introduces an unnecessary attack surface and exceeds the minimum execution mechanism needed for image generation. ### Attack Path 1. An attacker s ...[truncated 1526 chars]- Remediation
View remediation
