T09 · Insecure Skill Coding Practices
- Location
SKILL.md:49- Finding
Shell Command Injection Through Unsafe Dynamic Argument Interpolation
- Content
View full analysis
" --timeout 120 ### Start Xichun to generate an image openclaw agent --agent xichun --message "<图片提示词>" --timeout 180 ### Publish to the website cd ~/.openclaw/workspace/skills/post_to_website node post_skill.js "<作者>" "<文案>" "<标签>" "<图片路径>" ``` The archival workflow contains the same unsafe pattern: ```bash # Append content to the daily document node ~/.openclaw/workspace/skills/feishu-send-image/scripts/append_doc.js <文档token> <内容> # Upload an image to the document feishu_doc action=upload_image doc_token=<文档token> file_path=<图片路径> ``` ### Technical Analysis The Skill directs the agent to place user-controlled topics, AI-generated copy, image prompts, document content, tokens, and file paths directly into shell command templates. Double quotes do not make arbitrary data safe for shell execution. Shell constructs such as `$(command)` and backtick command substitution are still evaluated inside double-quoted arguments. The archival command is more exposed because its dynamic arguments are not quoted at all, allowing whitespace, command separators, redirections, pipes, and substitutions to affect command parsing. For example, a topic containing `$(malicious-command)` could cause the command to execute while the shell is constructing the `--message` argument. Likewise, unquoted archival content containing `; malicious-command` could terminate the intended command and start another one. The risk applies whenever these documented templates are instantiated as shell command strings. Final publication confirmation is not a sufficient mitigation because the topic and prompt commands are executed earlier in the workflow, and dangerous shell syntax may be concealed ...[truncated 1909 chars]- Remediation
View remediation
