T09 · Insecure Skill Coding Practices
- Location
SKILL.md:51- Finding
Unvalidated Values Are Interpolated into Shell Commands
- Content
View full analysis
-n ``` ```bash kubectl port-forward 8080: -n ``` ```bash kubectl auth can-i --as= -n kubectl get role -n kubectl get clusterrole kubectl get rolebinding -n kubectl get clusterrolebinding ``` ```bash kubectl exec -it -n -- nslookup kubectl exec -it -n -- cat /etc/resolv.conf ``` ```bash kubectl logs -n kube-system kube-apiserver- ``` ```bash kubectl patch pod -n --type='json' -p='[{"op": "replace", "path": "/spec/containers/0/resources/limits/memory", "value": "2Gi"}]' kubectl delete pod -n kubectl patch svc -n --type='json' -p='[{"op": "replace", "path": "/spec/ports/0/targetPort", "value": 8080}]' ``` ### Technical Analysis The Skill instructs an Agent with shell access to substitute user-provided or dynamically discovered values directly into command strings. Parameters such as ``, ``, ``, ``, and resource names are not accompanied by validation, escaping, or safe argument-passing requirements. If the Agent constructs these commands through a shell, a malicious value containing command separators, command substitution, redirection, or other shell metacharacters could escape the intended argument and execute an additional local command. The risk is particularly significant for values copied from a troubleshooting request without validating them against Kubernetes naming rules. The Skill does not require: - Canonical validation of Kubernetes resource names and namespaces. - Strict validatio ...[truncated 1837 chars]- Remediation
View remediation
