T09 · Insecure Skill Coding Practices
- Location
scripts/huawei_cloud/dispatcher.py:31- Finding
Cluster awakening bypasses the documented confirmation gate
- Content
View full analysis
Vulnerability Details
File Location:
scripts/huawei_cloud/dispatcher.py:31-33
Related Documentation:SKILL.md:25-35
Vulnerability Type: Missing authorization confirmation for a high-risk cloud operation
Risk Level: MediumVulnerable Code Snippet:
python # Cluster (query + lifecycle, excluding create/bind which need special logic) "huawei_list_cce_clusters": ("CCE", "ListClusters", ("region",), False), "huawei_delete_cce_cluster": ("CCE", "DeleteCluster", ("region", "cluster_id"), True), "huawei_hibernate_cce_cluster": ("CCE", "HibernateCluster", ("region", "cluster_id"), True), "huawei_awake_cce_cluster": ("CCE", "AwakeCluster", ("region", "cluster_id"), False),The Skill documentation states:
markdown This skill strictly enforces a two-step confirmation mechanism for all dangerous operations. All dangerous operations require `confirm=true` parameter to execute. | `huawei_awake_cce_cluster` | Awake | 🟠 High | Resumes cluster from hibernation |Technical Analysis
The dispatcher represents each simple operation as a tuple whose final Boolean controls confirmation enforcement. For
huawei_awake_cce_cluster, that value isFalse, even though the operation is classified as high risk in the Skill's security constraints.The generic handler only applies its confirmation gate when that Boolean is true:
python if confirm_required and params.get("confirm", "").lower() != "true": return { "success": False, "requires_confirmation": True, "error": "Confirmation required. Add confirm=true to proceed.", "hint": f"Add confirm=true parameter to confirm this operation.", }Consequently, a call without
confirm=trueproceeds torun(...), which invokes the authenticated Huawei CloudCCE AwakeClusteroperation. The executable path therefore fails to enforce the documented second-step authorization boundar ...[truncated 1187 chars]- Remediation
View remediation
Remediation Suggestions
- Change the dispatcher registration to enforce confirmation:
python "huawei_awake_cce_cluster": ( "CCE", "AwakeCluster", ("region", "cluster_id"), True, ),-
Add an automated test that invokes
huawei_awake_cce_clusterwithoutconfirm=trueand verifies:- The response contains
requires_confirmation: true. - No
hcloudsubprocess or cloud API request occurs.
- The response contains
-
Add a positive test verifying that the operation executes only when
confirm=trueis explicitly supplied. -
Keep the operation table and
SKILL.mdgenerated from, or validated against, a single authoritative risk-policy mapping to prevent future documentation/code drift. -
Review other state-changing operations to ensure their executable confirmation flags match the documented security constraints.
