T09 · Insecure Skill Coding Practices
- Location
claw_orch.py:33- Finding
User-Controlled Task Enables Shell Command Injection
- Content
View full analysis
Vulnerability Details
File Location:
claw_orch.py, lines 33-46
Vulnerability Type: OS command injection through an interpolated shell command
Risk Level: HighVulnerable Code
python prompt = f"""{task} Write the complete deliverable files NOW. Do not describe what you'll do - just write the files. Use the Write tool. No conversation, no explanation. Execute immediately.""" cmd = f'"{NODE}" "{NPX}" claude -p "{prompt}" --allowedTools "Read,Write" --permission-mode bypassPermissions --max-turns 5' print(f"🧠 CC Agent (claude-sonnet-4.6) 分析+生成中...", flush=True) env = os.environ.copy() env["PATH"] = os.path.dirname(NODE) + ";" + env.get("PATH", "") r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=180, cwd=WORKDIR, env=env, encoding="utf-8", errors="replace")Technical Analysis
The task originates from command-line arguments or interactive user input and is inserted into
promptwithout validation or escaping. That prompt is then placed inside a quoted command string and executed usingsubprocess.run(..., shell=True).Because the operating-system shell parses the resulting string, an attacker can include a closing quotation mark and shell control operators in the task. This terminates the intended
-pargument and introduces an independent command. Quoting the surrounding argument is insufficient because attacker-controlled quotation marks are not escaped.Attack Path
- An attacker supplies a crafted task through
sys.argvor the interactive prompt. - The task contains a quotation mark followed by Windows shell operators such as
&. - The task is interpolated into
cmd, breaking out of the intended-pargument. subprocess.run()passes the entire command string to the shell becauseshell=True.- The shell executes the injected command with the privileges and environment of the user running the orchestrator.
...[truncated 724 chars]
- An attacker supplies a crafted task through
- Remediation
View remediation
Remediation Suggestions
-
Eliminate shell interpretation and pass each command argument separately:
python cmd = [ NODE, NPX, "claude", "-p", prompt, "--allowedTools", "Read,Write", "--permission-mode", "default", "--max-turns", "5", ] r = subprocess.run( cmd, shell=False, capture_output=True, text=True, timeout=180, cwd=WORKDIR, env=env, encoding="utf-8", errors="replace", check=False, ) -
Do not attempt to fix the issue solely through manual shell escaping; avoiding a shell is substantially safer.
-
Impose task length limits and reject control characters where they are not required.
-
Run the delegated process in an isolated, minimally privileged account or sandbox.
-
Add regression tests containing quotation marks, ampersands, pipes, redirection characters, and line breaks.
-
