T09 · Insecure Skill Coding Practices
- Location
references/audit-script-decision.sh:117- Finding
Fake-Precision Warnings Do Not Affect the Final Audit Result
- Content
View full analysis
2 ? LINENUM-2 : 1)),$((LINENUM+2))p" "$TARGET_FILE") if echo "$CONTEXT" | grep -qi '(est\|含估算\|estimated\|approx'; then pass "Line $LINENUM: precise % found but labeled as estimate — OK" else warn "Line $LINENUM: precise % figure without '(est.)' label: $CONTENT" fi done ``` ### Technical Analysis In Bash, a loop on the right-hand side of a pipeline normally executes in a subshell. The `pass` and `warn` functions increment the global `PASS` and `WARN` counters, but calls made inside this piped `while` loop modify only the subshell's copies of those variables. When the loop terminates, the modified counters are discarded. As a result, the script may print a warning for an unlabeled high-precision percentage while leaving the parent process's `WARN` counter unchanged. The final summary and exit status are calculated from the unchanged parent counter. This creates a validation bypass in a script intended to act as a decision-document quality gate. ### Attack Path 1. Prepare a decision document that satisfies all other blocking and warning checks. 2. Include an unlabeled high-precision percentage such as `+12.85%`. 3. The script detects the value and invokes `warn` inside the piped loop. 4. The warning is printed, but the increment to `WARN` occurs only in the subshell. 5. After the pipeline finishes, the parent shell still has `WARN=0`. 6. The audit can return exit code `0` and report that all checks passed. ### Impact Assessment The flaw does not provide operating-system privileges, code ...[truncated 405 chars]- Remediation
View remediation
2 ? LINENUM-2 : 1)),$((LINENUM+2))p" "$TARGET_FILE") if printf '%s\n' "$CONTEXT" | grep -qiE '\(est|含估算|estimated|approx'; then pass "Line $LINENUM: precise % found but labeled as estimate — OK" else warn "Line $LINENUM: precise % figure without '(est.)' label: $CONTENT" fi done < <(printf '%s\n' "$PRECISION_LINES") ``` Security and reliability hardening should also include: 1. Add a regression test containing an unlabeled value such as `+12.85%`. 2. Assert that the test produces at least one warning and exit code `2`. 3. Add a corresponding test for a properly labeled estimate and verify that it does not generate a warning. 4. Run the script under both supported Bash versions and operating systems to verify consistent pipeline behavior. ]]>
