T09 · Insecure Skill Coding Practices
- Location
SKILL.md:20- Finding
Potential Command Injection Through Unsafely Constructed CLI Arguments
- Content
View full analysis
--values-json '[["..."]]'`] ## Schema Example ```json { "command": "gog sheets append sheet_id_123 \"Tab1!A:C\" --values-json '[[\"Val1\", \"Val2\", \"Val3\"]]' --json" } ``` ``` ### Technical Analysis The skill directs an agent to construct and execute a shell command containing dynamic spreadsheet identifiers, ranges, and row values. It does not require validation of these fields or mandate shell-free process execution with an explicit argument array. The JSON value passed to `--values-json` is enclosed in shell single quotes. If untrusted row data contains an apostrophe, it can terminate the quoted argument. Additional shell metacharacters could then be interpreted by the shell rather than passed to `gog` as data. Even without malicious input, legitimate values containing apostrophes can corrupt the command and cause incorrect writes or execution failures. Exploitability depends on the implementing agent interpolating untrusted values into the documented command and invoking it through a shell. The document does not itself contain an active payload, but its prescribed construction pattern lacks the controls needed to prevent this condition. ### Attack Path 1. An attacker controls or influences a spreadsheet ID, range, or row value supplied to the skill. 2. The attacker places a quote-breaking sequence and shell syntax in that input. 3. The agent serializes or directly interpolates the input into the documented `gog sheets append ... --values-json '...'` command. 4. The agent executes the constructed command through a shell. 5. The single-quoted JSON argument is terminate ...[truncated 857 chars]- Remediation
View remediation
