T09 · Insecure Skill Coding Practices
- Location
SKILL.md:150- Finding
Persistent Shell Command Injection Through Unsanitized Cron Keyword
- Content
View full analysis
` - Execution frequency: Daily at 10:00 (`0 10 * * *`) - Execution command: `python3 /search_douyin.py ""` (append `--start-date`/`--end-date` when applicable) - Generic crontab: `0 10 * * * python3 /path/to/search_douyin.py ""` ``` The displayed labels are English translations of the original documentation. The vulnerable command templates are unchanged in substance: ```bash python3 /search_douyin.py "" 0 10 * * * python3 /path/to/search_douyin.py "" ``` ### Technical Analysis The Skill instructs the agent to interpolate a user-derived keyword directly into a shell command stored in a crontab entry. Wrapping the value in double quotes does not make it safe: a keyword containing a double quote can terminate the quoted argument, after which shell separators, command substitutions, redirections, or additional commands can be injected. For example, the following malicious keyword: ```text "; touch /tmp/cron-injection; # ``` would produce a command equivalent to: ```bash python3 /path/to/search_douyin.py ""; touch /tmp/cron-injection; #" ``` When cron invokes its configured shell, the search script runs with an empty keyword and the injected `touch` command is then executed separately. This flaw is especially consequential because the unsafe command is placed in a persistent scheduled task. The daily subscription feature is explicitly documented and requires confirmation, so scheduling by itself is not treated as unauthorized persistence. Nevertheless, unsafe interpolation lets an attacker transform a legitimate subscription into recurring arbitrary command execution. ### Attack Path 1. An attacker persuades a user or an in ...[truncated 1488 chars]- Remediation
View remediation
