T09 · Insecure Skill Coding Practices
- Location
SKILL.md:131- Finding
Shell Command Injection Through User-Controlled Calendar Values
- Content
View full analysis
" add --noprompt --title "" --when "<Start>" --duration <minutes> gcalcli --nocolor --calendar "<Cal>" add --noprompt --allday --title "<Title>" --when "<Date>" ``` ```bash echo 'BEGIN:VCALENDAR VERSION:2.0 BEGIN:VEVENT DTSTART;VALUE=DATE:20260308 SUMMARY:Event Title RRULE:FREQ=YEARLY TRANSP:TRANSPARENT END:VEVENT END:VCALENDAR' | gcalcli import --calendar "<Cal>" ``` ```bash gcalcli --nocolor delete --iamaexpert "<query>" <start> <end> ``` ### Technical Analysis The Skill instructs the agent to interpolate conversationally supplied calendar names, event titles, dates, times, durations, and search queries into shell command strings. It does not require argument-array execution, escaping, validation, or another mechanism that prevents shell interpretation. Double quotes do not neutralize all shell syntax. Command substitutions such as `$(command)` and backticks can still execute inside double-quoted arguments. A quotation mark may also terminate the expected argument and introduce shell operators. In the ICS example, event data is placed inside a single-quoted `echo` operand; an apostrophe in generated content can terminate that operand and alter the resulting command. The issue applies when an execution environment passes the constructed command through a shell. If the execution tool uses a direct process API with separately encoded arguments, shell injection would be prevented, but the Skill does not mandate that safer execution model. ### Attack Path 1. An attacker causes the user or agent to process a crafted calendar name, event title, or deletion query. 2. The value includes shell metacharacters or command substitution, such as `$(attacker-command)`. 3. The agent substitutes the value into one of the documented com ...[truncated 713 chars]- Remediation
View remediation
