T09 · Insecure Skill Coding Practices
Error
- Location
SKILL.md:17- Finding
Command Injection Through Unquoted Google Drive Parameters
- Content
View full analysis
--out `] ``` ### Technical Analysis The skill directs the agent to construct and execute a terminal command by inserting a Google Drive file ID and a local output path into a shell-command template. Neither dynamic parameter is quoted or validated, and the skill does not require execution through a shell-free argument-array API. If an attacker can influence either `fileId` or `localPath`, shell metacharacters such as command separators, substitutions, or redirection operators could be interpreted by the shell rather than passed to `gog` as literal argument data. This can result in arbitrary command execution. The vulnerability is exploitable when the generated command is passed to a shell. Shell-free process invocation with separately supplied arguments would prevent shell parsing, but the current directive does not impose that requirement. ### Attack Path 1. An attacker provides a malicious Google Drive file ID or requested output path containing shell syntax. 2. The agent inserts the attacker-controlled value into the documented command template. 3. The agent executes the generated command through a terminal shell. 4. The shell interprets the injected metacharacters and executes the attacker's additional command. 5. The injected command runs with the same operating-system privileges and environment access as the agent. For example, an output-path value structured as a legitimate path followed by a shell command separator could cause the intended download command and an attacker-selected command to be executed sequentially. ### Impact Assessment Successful exploitation permits arbitrary co ...[truncated 698 chars]- Remediation
View remediation
