T09 · Insecure Skill Coding Practices
- Location
index.js:89- Finding
Shell Command Injection Through an Attacker-Controlled Search Keyword
- Content
View full analysis
{ const cmd = `"${this.pythonEnv}" "${this.pythonScript}" "${command}"`; exec(cmd, { cwd: __dirname, encoding: 'utf8', timeout: 120000, maxBuffer: 1024 * 1024 * 10 }, (error, stdout, stderr) => { if (error) { resolve({ success: false, error: stderr || error.message }); } else { resolve({ success: true, output: stdout }); } }); }); } ``` ### Technical Analysis The search keyword originates from an incoming OpenClaw message and is directly interpolated into a command string passed to Node.js `child_process.exec()`. The `exec()` function invokes a system shell, so embedded shell syntax is interpreted rather than treated solely as a Python argument. Wrapping the value in double quotes is not a sufficient defense. POSIX shells still process command substitution inside double quotes, and platform-specific metacharacters or quoting rules may allow argument termination and command injection on Windows. No allowlist, escaping routine, or control-character validation is applied before shell execution. This behavior exceeds the privileges required to run the crawler. The Skill only needs to launch a fixed Python interpreter with a fixed script and one data argument; it does not require a shell. ### Attack Path 1. An attacker gains permission to submit a `run-xhs` message through a Feishu group ...[truncated 1201 chars]- Remediation
View remediation
