T09 · Insecure Skill Coding Practices
- Location
SKILL.md:38- Finding
Shell Command Injection Through Untrusted Skill Arguments
- Content
View full analysis
') - date.fromisoformat('')).days)" ``` ```bash python3 "/wxpublic_list.py" "" "" "" "" "" ``` ```bash mkdir -p "/images" ``` ```bash python3 "/wxpublic_fetch.py" "" --manifest "/.wxpublic-articles.json" ``` ### Technical Analysis The Skill instructs the agent to interpolate user-controlled parameters directly into shell command strings. Affected inputs include the public-account name, dates, output directory, AppID, and SecretKey. Enclosing an interpolated value in double quotes does not neutralize shell command substitution. If the resulting command contains syntax such as `$(command)` or backticks, the shell can evaluate it before launching the intended program. The date calculation is additionally vulnerable to quoting attacks because values are inserted into both a shell-quoted Python expression and Python string literals. The default output path incorporates the user-controlled public-account name, so command injection may remain possible even when the user does not explicitly supply `--output`. Whether exploitation occurs depends on the agent constructing and executing these command templates as directed. The instructions provide no validation or context-appropriate escaping requirements. ### Attack Path 1. An attacker supplies a crafted argument containing shell syntax, such as a public-account name or output directory containing `$(attacker-command)`. 2. The Skill parser treats the value as an ordinary argument. 3. The agent substitutes the value into one of the documented Bash command templates. 4. Bash performs command substitution while parsing the generated command, i ...[truncated 801 chars]- Remediation
View remediation
