Skip to content

Coding-agent command validator approves a command trace whose composition executes a dangerous action

coding-agent-command-trace-composition is a high severity check in the ai category, written in shell. Its source is templates/ai/coding-agent/coding-agent-command-trace-composition.sh in cert-x-gen-templates.

Feeds a coding-agent’s command validator a session TRACE of individually-benign statements - bind a bare token, bind another, concatenate the two approved names, then invoke the result - each of which the validator allows on its own. The composition assembles a command the validator never judged as a whole and executes it, dropping a decoy marker. CONFIRMED when every statement is allowed yet the marker action fires; REFUTED when the validator re-validates the resolved, composed command and blocks it; SKIP when no command-trace validator surface is present. The check is inherently stateful - it is the sequence across observations that carries the finding, which per-item (per-skill / per-command) scanning structurally cannot follow.

Field Value
Id coding-agent-command-trace-composition
Severity high
Language shell
Category ai
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 90
CVSS not recorded
Weakness CWE-77
Tags ai, coding-agent, cli, command-validator, composition-bypass, trace, stateful, cwe-77, cwe-693, cwe-807
Target kind cli
Oracle property

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info coding-agent-command-trace-composition

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.