T09 · Insecure Skill Coding Practices
- Location
SKILL.md:18- Finding
Command Injection Through Unquoted Dynamic Parameters
- Content
View full analysis
--role reader --type user --email `] ``` ### Technical Analysis The documented command places the dynamic `fileId` and `email` values directly into a terminal command without specifying validation, quoting, or shell-safe argument handling. If an agent executes the generated text through a command shell, shell metacharacters embedded in either value could be interpreted as command syntax rather than as data. For example, a malicious value containing command separators or command substitution syntax could append an unintended command to the legitimate `gog drive share` invocation. The vulnerability is particularly significant because file identifiers and recipient addresses may originate from user-controlled requests. Exploitation depends on the agent substituting attacker-controlled input into the command and invoking it through a shell. The document does not provide safeguards against this behavior. ### Attack Path 1. An attacker asks the agent to share a file and supplies a maliciously crafted file identifier or email argument containing shell syntax. 2. The agent substitutes the supplied value into the documented command without validation or escaping. 3. The agent submits the resulting command to a shell-backed terminal tool. 4. The shell interprets the injected metacharacters. 5. The attacker's appended command executes with the same operating-system privileges and environment access as the agent or `gog` process. ### Impact Assessment Successful exploitation could permit arbitrary local command execution under the account running the agent. Depending on that account's privileges, t ...[truncated 385 chars]- Remediation
View remediation
