T09 · Insecure Skill Coding Practices
- Location
SKILL.md:17- Finding
Shell Command Injection Through Unsanitized Google Drive Search Query
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17-19
Vulnerability Type: Shell command injection
Risk Level: HighVulnerable Code
markdown ## Cognitive Directives WHEN [A file or folder needs to be located in Google Drive] THEN [Execute the native terminal command `gog drive search "query" --json`]Technical Analysis
The skill directs the agent to insert a search query into a native terminal command. It does not require validation, shell escaping, or execution through an argument-array API.
If an agent replaces the
queryplaceholder with attacker-controlled text and invokes the resulting string through a shell, embedded quotation marks and shell operators can terminate the intended argument and introduce additional commands.For example, a search query such as:
text "; id; #could produce:
sh gog drive search ""; id; #" --jsonWhen interpreted by a compatible shell, this runs
idas a separate command. The exact payload and available operators depend on the operating system and shell used by the agent.Attack Path
- An attacker controls or influences a request that asks the agent to locate a file or folder in Google Drive.
- The attacker supplies a crafted search query containing a closing quotation mark and shell control operators.
- The agent substitutes that query into the documented
gog drive search "query" --jsoncommand. - The agent executes the constructed command through a command shell.
- The shell interprets the injected operators and executes the attacker's additional command with the privileges of the agent process.
Impact Assessment
Successful exploitation could permit arbitrary local command execution under the account running the agent. The attacker could potentially read files available to that account, access environment variables or locally stored credentials, alter writable files, invoke network utilities, or perform other operations allowed by the agent's o ...[truncated 322 chars]
- Remediation
View remediation
Remediation Suggestions
-
Invoke
gogthrough a process-execution API that accepts an argument array and does not use a shell. Pass the search query as a single argument, conceptually equivalent to:text ["gog", "drive", "search", user_query, "--json"] -
Update the skill directive to explicitly prohibit concatenating user input into shell command strings and prohibit shell-enabled execution options.
-
If shell execution cannot be avoided, apply operating-system-specific shell escaping to the entire query. Generic quote replacement is not sufficient across all supported operating systems.
-
Validate input according to the expected Google Drive search syntax. Reject control characters and unnecessary shell metacharacters, while treating validation only as defense in depth rather than a substitute for shell-free execution.
-
Run the command with least privilege, a restricted environment, and no unnecessary access to local credentials or sensitive files.
-
Add security tests using inputs containing quotation marks, semicolons, command substitutions, pipes, redirection operators, newlines, and platform-specific command separators. Verify that every test value reaches
gogas exactly one inert argument.
-
