T09 · Insecure Skill Coding Practices
- Location
workflow.json:23- Finding
Shell Command Injection Through Unvalidated Repository Identifiers
- Content
View full analysis
Vulnerability Details
File Location:
workflow.json, lines 23-25
Vulnerability Type: OS command injection through unsafe placeholder interpolation
Risk Level: HighVulnerable Code
json "commands": [ "gh repo view {owner}/{repo} --json name,description,language,stargazerCount,pushedAt,license", "gh api repos/{owner}/{repo}/languages --jq '.'", "gh api repos/{owner}/{repo}/contents --jq 'map({name, type})'" ]Related command templates using the same placeholders also appear at lines 39, 53, and 83-85.
Technical Analysis
The workflow inserts the user-provided
ownerandrepovariables directly into shell command strings. No allowlist validation, escaping procedure, or structured argument construction is defined.If the workflow engine executes these command strings through a shell, repository identifiers containing shell metacharacters can alter the command structure. Quoting the URL in some related templates does not provide complete protection because an attacker may supply quote characters, command substitutions, or other shell syntax capable of leaving the intended quoting context.
Repository identifiers should be treated as untrusted input even when they are normally expected to follow GitHub naming rules. The workflow does not enforce those rules before command construction.
Attack Path
- An attacker supplies a specially crafted repository owner or repository name through a supported trigger.
- The workflow substitutes that value into one or more command templates.
- The resulting command string is passed to a shell.
- Embedded shell syntax terminates or modifies the intended
ghcommand. - The injected command executes with the privileges and environment of the Agent process.
Impact Assessment
Successful exploitation can provide arbitrary command execution under the account running the workflow. The attacker could read files accessible to that acc ...[truncated 358 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not build executable shell strings from user-controlled values.
- Invoke
ghthrough a process API that accepts an argument array, with shell execution disabled. - Validate
ownerandrepobefore use against strict GitHub-compatible allowlists. - Reject whitespace, quote characters, path separators outside the expected delimiter, command substitutions, control characters, and shell metacharacters.
- Construct API paths with a URL/path encoding library rather than textual concatenation.
- Apply the same correction to all related templates at lines 39, 53, and 83-85.
- Run the workflow under a minimally privileged account without unnecessary filesystem access or sensitive environment variables.
- Add tests containing quotes, semicolons, substitutions, newlines, and other adversarial input to verify that each value remains one literal process argument.
