T09 · Insecure Skill Coding Practices
- Location
SKILL.md:60- Finding
Shell Command Injection Through Unvalidated Git-Derived Values
- Content
View full analysis
/_` - `slug`: Extract the core noun from the user's description, use lowercase English with underscores, and limit it to 24 characters. - `gitUser`: Run `git config user.name` and use its value directly; if it contains spaces or uppercase characters, lowercase it and remove spaces. ``` The resulting value is inserted into a Bash command without mandatory validation or shell-safe argument handling: ```bash git status --porcelain git fetch origin git checkout master git pull --ff-only origin master git checkout -b /_ ``` The current branch name is also stored as `WORK_BRANCH` and inserted into multiple command templates: ```markdown 1. **Environment validation**: - `git rev-parse --abbrev-ref HEAD` must not be `master` or `develop`. - `git status --porcelain` must be empty. - Record the current branch name as `WORK_BRANCH`. ``` ```bash git push -u origin ``` ```bash git checkout develop git pull --ff-only origin develop git merge --no-ff git push origin develop ``` ```bash git checkout ``` The production workflow repeats the same unsafe pattern: ```bash git fetch origin git merge origin/master git push -u origin ``` ```bash git checkout master git pull --ff-only origin master git merge --no-ff git push origin master ``` ```bash git checkout ``` ### Technical Analysis The Skill directs the Agent to perform all Git operations through Bash. Both `gitUser` and `WORK_BRANCH` origin ...[truncated 3037 chars]- Remediation
View remediation
