T09 · Insecure Skill Coding Practices
- Location
SKILL.md:17- Finding
Shell Injection Through Unsafe API-Key Interpolation
- Content
View full analysis
" ``` ``` ### Technical Analysis The skill instructs the agent to interpolate an API key supplied through the conversation directly into a quoted shell command. Quotation alone does not safely encode an untrusted shell argument. A value containing a quotation mark followed by shell metacharacters can terminate the intended argument and introduce additional shell commands. The Python argument parser does not create this vulnerability by itself. The vulnerability occurs before Python starts, when a shell interprets the command assembled according to the skill instructions. For example, a malicious value shaped like the following could escape the quoted argument when substituted literally: ```text "; id > /tmp/injection-result; # ``` This issue is exploitable when the agent follows the documented workflow using a shell-based execution tool. ### Attack Path 1. An attacker presents a crafted string as a Semantic Scholar API key in the conversation. 2. The skill requires the agent to substitute that string into the documented `--api-key` command. 3. The agent sends the resulting command to a shell. 4. The injected quotation mark terminates the intended API-key argument. 5. Shell metacharacters introduce and execute an attacker-selected command. 6. The injected command runs with the same operating-system identity and permissions as the agent process. ### Impact Assessment Successful exploitation permits arbitrary command execution within the agent's local security context. The attacker could read files accessible to the agent, modify project content, steal environment var ...[truncated 246 chars]- Remediation
View remediation
