T09 · Insecure Skill Coding Practices
- Location
scripts/test-cli-commands.sh:69- Finding
Verification Script Performs Destructive Cloud Operations Without Enforced Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/test-cli-commands.sh, lines 69–103
Vulnerability Type: Missing confirmation gate for destructive operations
Risk Level: HighComplete Code Snippet:
bash SERVICE_ID=${SERVICE_ID:-} if [ -n "$SERVICE_ID" ]; then echo "Test 4: Show service detail" cloudrobo infer show --service-id "$SERVICE_ID" echo "" echo "Test 5: Start service (user must confirm)" echo "WARNING: This starts the service, consuming pool resources. Press Ctrl+C to cancel." sleep 2 cloudrobo infer start --service-id "$SERVICE_ID" || echo "Start may fail if already running" echo "" echo "Test 6: Stop service (user must confirm)" echo "WARNING: This stops the service. Press Ctrl+C to cancel." sleep 2 cloudrobo infer stop --service-id "$SERVICE_ID" || echo "Stop may fail if already stopped" echo "" echo "Test 7: List logs (ms timestamps)" END_MS=$(date +%s%3N 2>/dev/null || echo "0") START_MS=$(( END_MS - 3600000 )) cloudrobo infer list-logs --service-id "$SERVICE_ID" --start-time "$START_MS" --end-time "$END_MS" --limit 50 || echo "Logs may be empty if service never ran" echo "" echo "Test 8: Update service (user must confirm)" echo "WARNING: This updates the service. Press Ctrl+C to cancel." sleep 2 cloudrobo infer update --service-id "$SERVICE_ID" --description "Updated by test" || echo "Update may fail" echo "" echo "Test 9: Delete service (user must confirm)" echo "WARNING: This deletes the service. Press Ctrl+C to cancel." sleep 2 cloudrobo infer delete --service-id "$SERVICE_ID" || echo "Delete may fail if service already gone" echo "" fiTechnical Analysis
The documented verification entry point is:
bash bash scripts/test-cli-commands.shWhen the process environment contains a nonempty
SERVICE_ID, the script automatically starts, stops, updates, and ultimately deletes that inference servi ...[truncated 2245 chars]- Remediation
View remediation
Remediation Suggestions
-
Make all mutating tests opt-in through an explicit option, such as:
bash bash scripts/test-cli-commands.sh --run-mutating-testsKeep the default execution path strictly read-only.
-
Require an affirmative interactive response immediately before each mutation:
bash read -r -p "Start service $SERVICE_ID? Type YES to continue: " answer [ "$answer" = "YES" ] || exit 1 -
Require a separate, stronger confirmation for deletion, including the exact service ID:
bash read -r -p "Type the service ID to confirm permanent deletion: " answer [ "$answer" = "$SERVICE_ID" ] || exit 1 -
Refuse destructive execution in non-interactive environments unless a narrowly scoped, explicit confirmation mechanism is supplied. Do not treat a generic environment variable as authorization.
-
Prefer
--dry-runfor update and delete verification where supported. Separate destructive end-to-end tests from the ordinary smoke-test script. -
Validate the service with
showand display its workspace, name, and status before requesting confirmation, reducing the risk of acting on the wrong identifier. -
Remove the “Press Ctrl+C to cancel” pattern. A short cancellation window is not an acceptable replacement for positive confirmation.
-
