T09 · Insecure Skill Coding Practices
- Location
SKILL.md:121- Finding
Command Injection Through Unsafe CSV Interpolation
- Content
View full analysis
/tmp/desc_$$.md linear issue create --title "$title" --team "$team" --description-file /tmp/desc_$$.md --json rm -f /tmp/desc_$$.md ' ``` ### Technical Analysis The template substitutes each CSV row directly into a command string interpreted by `bash -c`. Because the substituted value appears inside shell source code rather than being passed as an inert argument, a row containing quotation marks, command substitutions, newlines, or other shell metacharacters can break out of the intended here-string and introduce arbitrary shell commands. The use of `IFS=, read` is also not a valid general-purpose CSV parser. Quoted fields, embedded commas, and embedded newlines can be parsed incorrectly, further increasing the likelihood that data will alter command structure. ### Attack Path 1. An attacker supplies or modifies an `issues.csv` file that the Agent is asked to import. 2. A CSV row contains shell syntax crafted to terminate the `<<< "{}"` expression and append an attacker-selected command. 3. The Agent follows the documented batch-import template. 4. `xargs` performs textual replacement of `{}` inside the `bash -c` command string. 5. Bash parses and executes the injected syntax with the privileges of the Agent process. 6. The injected process can access any files, environment variables, credentials, and network resources available to that account. ### Impact Assessment Successful exploitation provides arbitrary command execution under the operating-system account running the Agent. The resulting scope is not limited to Linear: it can include project files, environment variables, local credentials, writable filesystem locations, and network services accessible to the Agen ...[truncated 179 chars]- Remediation
View remediation
