T09 · Insecure Skill Coding Practices
Error
- Location
SKILL.md:20- Finding
Shell Command Injection Through Unsafely Interpolated Calendar Parameters
- Content
View full analysis
--summary "..."`] ## Schema Example ```json { "command": "gog calendar update primary event_id_123 --summary \"Updated Sync Meeting\" --json" ``` ### Technical Analysis The skill directs an agent to build and execute a shell command by placing the calendar ID, event ID, and requested summary directly into a textual command template. It does not require an argument-array execution API, input validation, or shell-safe escaping. The unquoted `` and `` placeholders are particularly exposed to shell metacharacter injection. Although the summary placeholder is surrounded by double quotes, this is not sufficient if a supplied summary contains quote characters, command substitutions, or other shell syntax. Directly substituting attacker-controlled content could therefore alter the command structure rather than passing the content exclusively as data to `gog`. The documented JSON command is also a serialized shell command string rather than a structured executable-and-arguments representation, encouraging unsafe concatenation and shell interpretation. ### Attack Path 1. An attacker controls or influences the calendar ID, event ID, or requested event summary supplied to the agent. 2. The attacker includes shell syntax in one of those values. For example, a malicious summary could close the quoted argument and append an additional command. 3. The agent interpolates the value into the documented command template. 4. The command is submitted to a shell rather than executed through a shell-free argument-array API. 5. The shell interprets the injected metacharacters and runs the ...[truncated 964 chars]- Remediation
View remediation
- - --summary - - --json ``` 2. Explicitly prohibit construction of a shell command string from user-controlled values. 3. Validate calendar and event identifiers against the narrowest syntax accepted by the service. Reject unexpected whitespace, control characters, and shell metacharacters where they are not valid identifier characters. 4. Treat the summary as opaque text and pass it as one literal process argument. Do not attempt to make it safe merely by surrounding it with quotation marks. 5. If shell execution is unavoidable, apply robust, platform-specific argument escaping to every dynamic value. Shell-free execution should remain the preferred control. 6. Update the skill documentation to state that the operation must modify only the summary and must not execute any command or option derived from summary contents. 7. Add negative tests using values containing quotes, semicolons, command substitutions, newlines, option prefixes, and other metacharacters. Confirm that each value reaches `gog` as a single literal argument. ]]>
