T09 · Insecure Skill Coding Practices
Warning
- Location
SKILL.md:18- Finding
Potential Command Injection Through Unvalidated CLI Arguments
- Content
View full analysis
--from "..." --to "..."`] ## Schema Example ```json { "command": "gog calendar update primary event_id_123 --from \"2026-04-28T10:00:00Z\" --to \"2026-04-28T11:00:00Z\" --json" } ``` ``` ### Technical Analysis The skill instructs an agent to construct a terminal command using dynamic calendar identifiers, event identifiers, and timestamp values. It does not require strict validation of those values, shell-safe escaping, or execution through a structured argument array. The calendar and event identifiers are shown without quoting. The timestamp values are enclosed in double quotes, but the instructions do not prevent embedded quotation marks, command substitutions, or other shell metacharacters. If the execution environment passes the constructed command through a shell, an attacker-controlled value could terminate an argument and append an additional command. The example itself contains benign static values. Exploitation therefore depends on the agent substituting untrusted input into the documented command and executing the resulting string through a command shell. ### Attack Path 1. An attacker supplies a crafted calendar ID, event ID, or timestamp through a rescheduling request. 2. The agent inserts the supplied value directly into the documented command template. 3. The generated command is submitted to a shell rather than executed as a structured process argument array. 4. Shell metacharacters in the supplied value alter the intended command structure. 5. The injected command executes with the operating-system permissions and environment available to the agent p ...[truncated 971 chars]- Remediation
View remediation
