T09 · Insecure Skill Coding Practices
- Location
SKILL.md:76- Finding
Unsafe Broad-Scope Process Termination and Log Deletion Instructions
- Content
View full analysis
` | Kill processes by name | | `pgrep -f ` | Find process PIDs | | `kill -9 ` | Forcefully terminate a process | | `nohup &` | Run a command in the background | ``` ```bash # Delete old logs, retaining the most recent seven days find /var/log -name "*.log" -mtime +7 -delete # Find the largest directories at depth two du -h --max-depth=2 / | sort -hr | head -20 # Kill all processes named Python pkill -f python ``` The usage guidance also maps a log-cleanup request directly to a destructive command: ```markdown - "Clean logs older than seven days" → execute `find ... -mtime +7 -delete` ``` ### Technical Analysis The Skill recommends commands that can delete files or terminate processes without requiring a preview, explicit confirmation, scope validation, privilege validation, or a recovery mechanism. `pkill -f python` matches against complete process command lines. It can therefore terminate unrelated Python applications, administrative scripts, monitoring agents, or other users' workloads rather than only the process intended by the user. The documented `kill -9` command immediately issues `SIGKILL`, preventing the target process from performing graceful shutdown, releasing resources, or flushing buffered data. The command targeting `/var/log` recursively deletes every matching `.log` file older than seven days within the invoking account's permissions. It does not restrict deletion to a specific application, verify that files are inactive, produce a reviewable manifest, or preserve security and audit records. If the Agent runs with elevated privileges, the deletion scope can include system-wide logs. `nohup &` additionally permits an arbitrary command to continue after the interac ...[truncated 2156 chars]- Remediation
View remediation
&` guidance with an allowlisted execution mechanism that records the command, PID, owner, logs, timeout, and cleanup procedure. 10. Apply least privilege so the Agent cannot alter system-wide logs or processes unless the task specifically requires that access. 11. Add guardrails requiring a dry run, affected-resource summary, scope check, and rollback or recovery plan before destructive operations. ]]>
