T09 · Insecure Skill Coding Practices
- Location
scripts/enforce_skill_policy.py:132- Finding
Broad rule-definition filtering allows policy detection bypass
- Content
View full analysis
Vulnerability Details
File Location:
scripts/enforce_skill_policy.py:132-160
Vulnerability Type: Policy scanner bypass through unsafe line exclusion
Risk Level: HighVulnerable Code
python def looks_like_rule_definition(line: str) -> bool: stripped = line.strip() if any(token in stripped for token in ("DEFAULT_POLICY", "forbidden_patterns", "warn_patterns")): return True if stripped.startswith(("- \"", "- '")): return True if stripped.startswith(("r\"", "r'")): return True if "_pattern = r" in stripped: return True if "line_of(text, r" in stripped: return True if stripped.startswith("- ") and ("\\s" in stripped or "\\b" in stripped or "\\(" in stripped): return True if re.search(r'"\w+[.\w-]+",\s*r"', stripped): return True return False def line_of(text: str, pattern: str, *, skip_rule_defs: bool = True) -> int | None: regex = re.compile(pattern, re.IGNORECASE) for index, line in enumerate(text.splitlines(), 1): if skip_rule_defs and looks_like_rule_definition(line): continue if regex.search(line): return index return NoneTechnical Analysis
The scanner excludes entire lines from security inspection when they superficially resemble policy or regular-expression definitions. These exclusions are based on broad textual characteristics rather than a trusted file location or structural parsing.
For example, any line containing
forbidden_patternsorwarn_patterns, beginning with a quoted list item, or beginning with a raw string is skipped before forbidden, network, secret-read, and warning patterns are evaluated. These formats can also legitimately occur in malicious scripts, Markdown instructions, shell arguments, or embedded payloads.Because
line_of()is shared by all content-pattern controls, this is a general-purpose bypass rather than a limitation of one rule.Attack P
...[truncated 1317 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove syntax-based whole-line exclusions from the generic matching function.
- Scan all candidate content by default.
- If bundled policy definitions must be excluded, identify them through an explicit trusted-file allowlist rather than attacker-controlled line contents.
- Prefer language-aware parsing where false positives must be suppressed.
- Apply exclusions only to the exact parsed string literal representing a rule, not to the entire line.
- Add regression tests covering:
- Dangerous content on quoted Markdown list lines.
- Raw Python strings containing prohibited operations.
- Variables or comments containing
forbidden_patterns. - Multiline command and subprocess arguments.
- Network and secret-read indicators embedded in apparent rule definitions.
- Fail closed when scanner parsing is ambiguous.
