T09 · Insecure Skill Coding Practices
- Location
scripts/db.py:297- Finding
Message approvals are not bound to the exact approved preview
- Content
View full analysis
str: approval_id = str(uuid.uuid4()) self.execute( """ INSERT INTO approvals ( id, action, target_type, target_id, decision, preview_json, decided_by, decided_at ) VALUES (?, ?, ?, ?, ?, ?, ?, ?) """, ( approval_id, action, target_type, target_id, decision, json.dumps(preview, ensure_ascii=False, sort_keys=True), decided_by, utc_now(), ), ) return approval_id def authorize_action( self, action: str, target_type: str, target_id: str ) -> str: with self.connection() as connection: connection.execute("BEGIN IMMEDIATE") row = connection.execute( """ SELECT id FROM approvals WHERE action = ? AND target_type = ? AND target_id = ? AND decision = 'approved' AND consumed_at IS NULL ORDER BY decided_at LIMIT 1 """, (action, target_type, target_id), ).fetchone() if row is None: raise ApprovalRequired( f"Approval required for {action} on {target_type}:{target_id}" ) approval_id = str(row["id"]) connection.execute( "UPDATE approvals SET consumed_at = ? WHERE id = ?", (utc_now(), approval_id), ) return approval_id ``` The send path calls this identifier-only authorization check: ```py ...[truncated 2548 chars]- Remediation
View remediation
