T09 · Insecure Skill Coding Practices
- Location
SKILL.md:27- Finding
Command Injection Through Unsafe User-Controlled URL Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent product-search purpose, but its documented curl template can become unsafe if user search text is substituted directly into a shell command.
Install only if you are comfortable sending product-search queries to trend-hunt.com, and avoid using the documented command by direct text substitution. The skill should be revised to require safe URL encoding or a structured HTTP client before routine use.
SKILL.md:27Command Injection Through Unsafe User-Controlled URL Interpolation
The trigger conditions are broad enough to activate on many ordinary recommendation or comparison requests, which can cause this external-search skill to be invoked more often than necessary. That increases the chance of unnecessary data egress to a third-party service and can bias responses toward ProductHunt/trend-hunt results even when the user did not specifically request that source.
No suspicious patterns detected.