T09 · Insecure Skill Coding Practices
- Location
scripts/cci_network_helper.py:170- Finding
Destructive Network Deletion Lacks an Enforced Confirmation Gate
- Content
View full analysis
Vulnerability Details
File Location:
scripts/cci_network_helper.py, lines 170-183 and 254-280
Vulnerability Type: Missing authorization confirmation for a destructive operation
Risk Level: MediumVulnerable code:
python def delete_network(namespace, name, region, project_id=None): ak, sk, security_token = get_credentials() if not project_id: project_id = get_project_id(region) host = f"cci.{region}.myhuaweicloud.com" resource_path = ( f"/apis/networking.cci.io/v1beta1/namespaces/{namespace}/networks/{name}" ) url = f"https://{host}{resource_path}" headers = sign_request( "DELETE", host, resource_path, "", ak, sk, security_token, project_id ) resp = requests.delete(url, headers=headers)python delete_parser = subparsers.add_parser( "delete", help="Delete a CCI Network" ) delete_parser.add_argument("--namespace", required=True) delete_parser.add_argument("--name", required=True) delete_parser.add_argument("--region", required=True) delete_parser.add_argument("--project-id", default=None) # ... elif args.action == "delete": delete_network( args.namespace, args.name, args.region, args.project_id )Technical Analysis
The Skill documentation requires two-step confirmation for destructive operations. In particular,
SKILL.mdlines 24 and 94-113 require the command and resource details to be previewed before execution, followed by explicit user confirmation.The helper script does not technically enforce that boundary. Its
deletesubcommand accepts the namespace, network name, region, and optional project ID, then immediately signs and sends an authenticated HTTPDELETErequest. It has no interactive prompt, confirmation token, explicit confirmation flag, or dry-run default.Consequently, a caller can bypass the documented preview-and-confirm workflow by ...[truncated 1303 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the helper's
deleteaction if network deletion is not required through this script. - Otherwise, default deletion to a non-destructive preview that displays the exact project, region, namespace, network, API endpoint, and operational consequences.
- Require an explicit confirmation mechanism before sending the request, such as an interactive prompt that repeats the exact resource identity.
- For non-interactive use, require a deliberate flag or confirmation token bound to the previewed resource rather than a generic
--yes. - Reject deletion when confirmation is absent or does not match the selected namespace and network.
- Consider requiring a dry-run or preflight lookup before confirmation so the user can verify the target resource.
- Preserve the documented two-step confirmation requirement in every executable entry point rather than relying solely on Agent instructions.
- Remove the helper's
