T09 · Insecure Skill Coding Practices
- Location
SKILL.md:738- Finding
Destructive scheduler configuration replacement lacks an enforced confirmation gate
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 738–742
Vulnerability Type: Destructive persistent configuration change without enforced confirmation
Risk Level: MediumRelevant snippet:
markdown | `schedule.job.depends.save` | POST | Full replacement of the job dependency list (existing entries are deleted before new entries are written, without a confirmation handshake; omitted dependencies are silently cleared). Supports OR/AND grouping through `dependGroup`. | 🟡 | | `schedule.job.plugins.list` | GET | Lists plugins bound to a job, by jobCode. | 🟢 | | `schedule.job.plugins.save` | POST | Full replacement of the job plugin list (existing entries are deleted before new entries are written, without a confirmation handshake; omitted bindings are silently cleared). | 🟡 |Technical Analysis
The Skill exposes
schedule.job.depends.saveandschedule.job.plugins.savethrough its generic API dispatcher. Both operations use full-replacement semantics: the platform deletes existing persistent configuration and then writes the supplied array.Unlike the separately documented
confirmRequired:trueoperations, these endpoints do not enforce a two-step confirmation handshake. The documentation recommends listing current bindings before constructing a replacement, but this is only procedural guidance. Neither the execution wrapper nor the documented server behavior requires evidence that the caller retrieved and reviewed the current configuration.Consequently, an Agent with the relevant write scope can directly submit an incomplete or empty replacement array. An omitted dependency or plugin is treated as an instruction to delete it, rather than as an unchanged field. This creates a reachable destructive-operation risk even without malicious project intent.
Attack Path
- The operator grants an Agent the scope required to manage scheduler dependencies or plugins.
- The Agent invokes `sche ...[truncated 1357 chars]
- Remediation
View remediation
Remediation Suggestions
- Add these full-replacement operations to the server-enforced
confirmRequired:trueworkflow. - Return a preview of entries that will be added, changed, and deleted before accepting confirmation.
- Require an expected configuration revision or ETag and reject stale replacement requests.
- Provide incremental add, update, and delete endpoints so routine changes do not require destructive replacement.
- If full replacement remains necessary, require an explicit destructive flag for requests that omit existing entries or supply an empty array.
- Enforce the protection server-side; documentation instructing callers to list current values first is not an adequate authorization or confirmation boundary.
- Add these full-replacement operations to the server-enforced
