T09 · Insecure Skill Coding Practices
- Location
SKILL.md:28- Finding
Shell Command Injection Through Unsafe User Query Interpolation
- Content
View full analysis
" \ --user-id "${BOOKING_API_USER_ID:-624e5b8b3f4a2f4ec566e3d3}" \ --env "${BOOKING_API_ENV:-prod}" \ --base-url "${BOOKING_API_BASE_URL:-http://host.docker.internal:8763}" ``` ```text - The `--query` value should be the user's **full original message** (do not rewrite or simplify) - The script outputs the assistant's reply to stdout; pass it back to the user verbatim ``` ### Technical Analysis The skill instructs the agent to insert the user's complete, unmodified message into a shell command inside double quotes. Double-quoted shell strings do not neutralize command substitutions such as `$(command)` or backticks. A message containing a closing quote can also terminate the argument and introduce shell operators. The Python script itself receives `--query` through `argparse` and does not invoke a shell. The vulnerability arises when an agent follows the documented shell template by constructing a command string and passing it to a shell rather than invoking the script with a structured argument array. For example, a travel-related message containing `$(attacker_command)` could be inserted into the documented command. If evaluated by a shell, the command substitution would run before Python receives the final argument. ### Attack Path 1. An attacker submits a travel query that includes shell metacharacters, command substitution, or quote-breaking syntax. 2. The skill is activated because the message also contains a flight, train, hotel, or travel request. 3. Following `SKILL.md`, the agent copies the complete original message into the `--query ""` portion of a shell command. 4. The execution environment evaluates the constructed command through a shell. 5. The shell executes the injected command before or along ...[truncated 756 chars]- Remediation
View remediation
