T09 · Insecure Skill Coding Practices
- Location
scripts/monitor.sh:153- Finding
Arbitrary Command Execution Through Unvalidated Arithmetic Expression
- Content
View full analysis
- Remediation
View remediation
&2 return 2 fi if [[ ! $3 =~ ^[0-9]+$ ]]; then echo "Error: --top must be a positive integer" >&2 return 2 fi top=$3 if (( 10#$top < 1 || 10#$top > 100 )); then echo "Error: --top must be between 1 and 100" >&2 return 2 fi fi echo "📊 Top $top Processes by CPU" echo "" case "$(get_os)" in macos|linux) ps aux --sort=-%cpu | head -n "$((10#$top + 1))" ;; esac } ``` Additional hardening measures: 1. Treat every command-line argument as untrusted input. 2. Validate values before placing them in arithmetic, test, or shell-evaluation contexts. 3. Use an explicit option parser rather than relying on positional assumptions. 4. Bound the process count to prevent excessive output or resource consumption. 5. Add regression tests containing malformed arithmetic expressions, command substitutions, negative values, very large values, and the documented `--top` syntax. 6. Run the skill under a least-privileged account so any future command-execution defect has reduced impact. ]]>
