Agent skill
detecting-command-injection
Detects OS command injection vulnerabilities by identifying unsafe system/popen/exec calls with user-controlled input. Use when analyzing command execution, shell operations, or investigating potential command injection points.
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/development/detecting-command-injection-waiwai24-binaryx-agent
SKILL.md
Command Injection Detection
Detection Workflow
- Identify command execution points: Find system(), popen(), execve(), ShellExecute(), CreateProcess() calls
- Trace input sources: Use
xrefs_toto trace command strings to user input (network, files, environment variables) - Check sanitization: Verify input validation, character escaping, command argument separation, safe API usage
- Assess exploitability: Can attacker inject special characters (;, &, |, `)? Control command arguments? Execute multiple commands?
Key Patterns
- Direct system() with unvalidated user input
- popen() with partial sanitization
- execve with insufficient validation
- Indirect command execution via environment variables
Output Format
Report with: id, type (system/popen/exec), severity, confidence, location, sink, source, command string, sanitization status, exploitability, payload example, mitigation.
Severity Guidelines
- CRITICAL: Direct use of system() with unvalidated user input
- HIGH: popen() with partial sanitization
- MEDIUM: execve with array but insufficient validation
- LOW: Command execution with strict whitelisting
See Also
patterns.md- Detailed detection patterns and exploitation scenariosexamples.md- Example analysis cases and code samplesreferences.md- CWE references and mitigation strategies
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
Didn't find tool you were looking for?