T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:119- Finding
Destructive-command confirmation can be bypassed through one-shot execution
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py:119-146
Vulnerability Type: Missing centralized authorization and confirmation enforcement
Risk Level: HighComplete Code Snippet
python def run_one_shot_fast(host, port, user, password, command, raw=False): """Fast mode: Use SSH ControlMaster to reuse connection First time ~1.5s, subsequent ~0.2s When raw=True, skip natural language parsing and execute raw command directly""" ctrl_path = _ensure_connection(host, port, user, password) if not ctrl_path: return run_one_shot_paramiko(host, port, user, password, command, raw=raw) # Raw mode: execute directly, bypass NL routing if raw: result = subprocess.run( ['ssh', '-o', f'ControlPath={ctrl_path}', '-o', 'ControlMaster=auto', '-o', 'BatchMode=yes', '-p', str(port), f'{user}@{host}', command], capture_output=True, text=True, timeout=60 ) if result.returncode == 0: if result.stdout.strip(): print(result.stdout.strip()) else: if result.stderr.strip(): print(f"❌ Error (exit {result.returncode}): {result.stderr.strip()}") elif result.stdout.strip(): print(result.stdout.strip()) return result.returncode # Determine if command is natural language # Strategy: if it looks like a shell command, execute directly; otherwise route to NL is_nl = not _is_shell_command(command) if is_nl: # Natural language goes through executor (requires paramiko connection) executor = CommandExecutor() connect_text = f"SSH connect {host} port {port} user {user} password {password}" executor.handle_command(connect_text) result = executor.handle_command(command) print(result) executor.session_manager.close_all_sessions() return 0 else: # Direct shell command goes through fast mode ...[truncated 3255 chars]- Remediation
View remediation
Remediation Suggestions
- Route every remote command, including one-shot, fast, fallback, and raw modes, through one centralized authorization function.
- Do not allow
--rawto bypass validation. If raw execution is required, apply the same blocked-command and confirmation policy before opening the SSH execution channel. - Require a non-replayable confirmation token bound to the exact command, target host, username, and expiration time.
- Default unrecognized commands to rejection or explicit confirmation instead of
CommandType.ALLOWED. - Parse shell command structure rather than relying only on anchored regular expressions. Account for wrappers, command substitution, pipelines, separators, redirections, and shell interpreters.
- Revalidate the exact final command immediately before execution so that command transformations cannot occur after confirmation.
- Add tests covering destructive commands through all entry paths, including
--raw, shell-looking--commandvalues, compound commands, and Paramiko fallback behavior.
