T09 · Insecure Skill Coding Practices
- Location
SKILL.md:217- Finding
Weak Workout Ownership Check Can Delete User-Created Schedule Entries
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 217-219
Related Command Location:references/gccli-commands.md, lines 216-220
Vulnerability Type:T09: Insecure Skill Coding Practices
Risk Level: MediumVulnerable Code
From
SKILL.md:text Before scheduling new workouts, automatically remove all existing future scheduled workouts created by this skill (identifiable by the "W" prefix naming convention like "W3 Tempo Run"). Do not ask for confirmation — these are skill-managed workouts. For workouts that don't match the W-prefix pattern (user-created), leave them in place and schedule around them.Related deletion command from
references/gccli-commands.md:bash # Remove automatically without confirmation — these are skill-created: gccli workouts schedule remove <schedule-id> --forceTechnical Analysis
The Skill uses a generic
W1throughW12workout-name prefix as the ownership test for destructive cleanup. A name is not reliable provenance metadata: users and other integrations can independently create workouts whose names match this convention.Consequently, the Skill may classify an unrelated workout as Skill-managed and pass its schedule ID to a forced removal command. The
--forceoption and explicit instruction not to request confirmation remove the final opportunity for the user to detect the incorrect classification.This behavior also conflicts with the stated requirement to preserve user-created workouts. The naming convention alone cannot establish whether this Skill created an entry.
Attack Path
-
A user or another Garmin integration creates and schedules a workout with a name such as
W3 Tempo Run. -
The user reruns the Garmin Trainer Skill.
-
The Skill lists future scheduled workouts.
-
It treats the matching
Wprefix as proof that the workout belongs to the Skill. -
It extracts the unrelated entry's schedule ID.
-
It runs:
bash gccli workouts schedule remo
...[truncated 639 chars]
-
- Remediation
View remediation
Remediation Suggestions
- Record the exact workout IDs and schedule IDs created by the Skill in dedicated state, then delete only entries whose identifiers match that state.
- If Garmin supports custom metadata, tags, or descriptions, add a collision-resistant ownership marker and verify both the marker and stored identifier before deletion.
- Do not treat a human-readable naming convention as proof of ownership.
- If ownership cannot be conclusively established, preserve the entry or present the candidate entries to the user and require explicit confirmation.
- Avoid
--forcefor ambiguous entries. Reserve forced deletion for entries whose ownership has been verified through stable identifiers. - Handle stale or missing state conservatively: reconstruct the plan around uncertain entries rather than deleting them.
- Add collision tests covering user-created and third-party workouts named with
W1throughW12prefixes.
