T09 · Insecure Skill Coding Practices
- Location
scripts/main.sh:6- Finding
Unrestricted Remote Action Forwarding
- Content
View full analysis
| gpio_off " # exit 1 代表程式異常終止(回傳非 0 值) exit 1 fi ``` ```bash curl -s http://$PI_IP:9000/run \ -H "Content-Type: application/json" \ -d "{\"action\": \"$ACTION\", \"pin\": $PIN}" ``` ### Technical Analysis The documented interface permits only `gpio_on` and `gpio_off`, but the script verifies only that `ACTION` is nonempty. It then forwards the value unchanged to the remote `/run` endpoint. The claim in `SKILL.md` that the Pi server restricts actions cannot be verified because the server implementation is not included in the audited project. Consequently, the client relies entirely on an external security control instead of enforcing the documented action boundary locally. ### Attack Path 1. An attacker or agent capable of invoking `scripts/main.sh` supplies an undocumented action: ```bash ./scripts/main.sh undocumented_action 17 ``` 2. The script accepts the nonempty action without checking it against an allowlist. 3. It sends the following request to the Pi: ```json {"action": "undocumented_action", "pin": 17} ``` 4. If the remote dispatcher exposes additional actions or inadequately validates action names, it may execute functionality outside the intended GPIO on/off interface. Exploitation beyond request submission is conditional on the behavior of the external server. ### Impact Assessment The confirmed impact is the ability to submit arbitrary action identifiers to the remote RPC endpoint. If the server has undocumented or privileged handlers, this could allow operations beyond GPIO switching with the privileges of the Pi RPC service. The precise server- ...[truncated 82 chars]- Remediation
View remediation
&2 exit 2 ;; esac ``` Additionally: - Maintain an explicit server-side allowlist independent of client validation. - Map accepted public action names to fixed internal handlers rather than dynamically evaluating or dispatching arbitrary strings. - Run the RPC service with only the GPIO permissions required for its intended function. - Return an error for every unknown action and log rejected requests without recording sensitive authentication material. - Add tests confirming that malformed, empty, and undocumented action names are rejected. ]]>
