T09 · Insecure Skill Coding Practices
- Location
scripts/test-cli-commands.sh:59- Finding
Verification Script Dispatches a Physical Robot Task Without Affirmative Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/test-cli-commands.sh, lines 59–70
Vulnerability Type: Missing confirmation gate for a physical, side-effecting operation
Risk Level: MediumVulnerable Code
bash # Test 5: Create task (mutating, needs confirmation) if [ -z "$TASK_ID" ]; then if [ -n "$ROBOT_ID" ] && [ -n "$EXEC_MODEL_ID" ]; then echo "Test 5: Create task (mutating)" echo "WARNING: This creates a dispatcher task. Press Ctrl+C to cancel." sleep 2 CREATE_RESULT=$(cloudrobo dispatch create-task \ --session-id "$SESSION_ID" \ --name "test-task-$(date +%s)" \ --task "Move forward 1 meter and report position" \ --constraints-json "{\"model\":{\"exec_model_id\":\"$EXEC_MODEL_ID\"},\"robot_id\":\"$ROBOT_ID\",\"exec_constraints\":{\"max_run_time\":10,\"max_iter_num\":100}}")Technical Analysis
The script labels task creation as requiring confirmation, but implements only a warning followed by a two-second delay. Unless the operator interrupts the process, it automatically submits a real task through the authenticated
cloudroboCLI.This is not an affirmative confirmation mechanism. It is also ineffective in unattended execution, where no operator may be present to press Ctrl+C. The task text is hardcoded to direct the selected robot to move forward one meter.
The issue is reachable when:
SESSION_IDis set.ROBOT_IDandEXEC_MODEL_IDare set.TASK_IDis unset.- The verification script is executed.
The documented safety model requires confirmation before task creation. Specifically,
SKILL.mdlines 350–351 and 434,references/verification-method.mdlines 9–10, and the confirmation sequence inreferences/dataflow-diagram.mdlines 32–34 all require user confirmation. The executable script does not enforce that requirement.Attack Path
- An operator configures valid CloudRobo credentials and environment variable ...[truncated 1435 chars]
- Remediation
View remediation
Remediation Suggestions
- Make verification non-mutating by default and invoke
create-taskwith--dry-run. - Require an explicit opt-in flag, such as
--execute-mutating-tests, before submitting any real task. - Add an affirmative interactive prompt that identifies the exact session, robot, execution model, and movement instruction. Continue only after an unambiguous response such as
yes. - Refuse real task creation in non-interactive environments unless a separate, explicit authorization mechanism is supplied.
- Prefer a dedicated simulator or clearly isolated test robot for lifecycle tests.
- Preserve the existing execution limits, but do not treat them as a substitute for confirmation.
- Ensure the executable behavior matches the confirmation requirements documented in
SKILL.mdand the reference documents.
- Make verification non-mutating by default and invoke
