T09 · Insecure Skill Coding Practices
- Location
scripts/test-cli-commands.sh:76- Finding
Verification Script Performs Destructive Cloud Operations Without Enforced Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/test-cli-commands.sh, lines 76–98
Vulnerability Type: Destructive authenticated operations without an enforced confirmation gate
Risk Level: HighVulnerable code:
bash if [ -n "$ROBOT_ID" ]; then echo "Test 6: Show robot detail" cloudrobo robot show --robot-id "$ROBOT_ID" echo "" echo "Test 7: Update robot (user must confirm)" echo "WARNING: This updates the robot. Press Ctrl+C to cancel." sleep 2 cloudrobo robot update --robot-id "$ROBOT_ID" --description "Updated by test" echo "" echo "Test 8: Export access config / certificate (user must confirm)" echo "WARNING: This exports the robot access config (zip) with password. Press Ctrl+C to cancel." sleep 2 mkdir -p ./certs cloudrobo robot export-certificate --robot-id "$ROBOT_ID" --password "temp-export-pw" --output ./certs || echo "Export may fail if certificate unavailable" echo "" echo "Test 9: Delete robot (user must confirm)" echo "WARNING: This deletes the robot. Press Ctrl+C to cancel." sleep 2 cloudrobo robot delete --robot-id "$ROBOT_ID" || echo "Delete may fail if robot already gone" echo "" fiTechnical Analysis
The documented verification command runs this script directly. If
ROBOT_IDis set, the script automatically performs three authenticated write operations against that robot:- It changes the robot description.
- It exports the robot access credential bundle.
- It irreversibly deletes the robot.
The warning messages and two-second sleeps are not confirmation controls. The script does not read an affirmative response, require a destructive-operation flag, verify an interactive terminal, or default these commands to
--dry-run.This contradicts the Skill's stated control in
SKILL.mdlines 333–334:markdown **Mutating operations** (create/update/delete/expor ...[truncated 1657 chars]- Remediation
View remediation
Remediation Suggestions
- Make all mutating tests opt-in and default the verification script to read-only or
--dry-run. - Require a dedicated flag such as
--allow-destructive-testsbefore entering the write-test block. - Before each mutation, display the exact robot ID and operation, then require an explicit affirmative response:
bash read -r -p "Delete robot '$ROBOT_ID' permanently? Type the robot ID to confirm: " confirmation [ "$confirmation" = "$ROBOT_ID" ] || exit 1 - Fail closed when standard input is not an interactive terminal unless a separately documented noninteractive confirmation mechanism is supplied.
- Require separate confirmations for update, certificate export, and deletion; do not treat one confirmation as authorization for all operations.
- Do not use a fixed certificate password. Prompt securely with
read -s, accept it through a protected mechanism, or generate a strong random password and disclose it only to the authorized user. - Write exported credentials to a user-selected protected directory with restrictive permissions, and clearly report the resulting sensitive file.
- Keep deletion disabled in routine smoke tests. If cleanup is needed, only delete a robot created by the same test run and verify its recorded identifier immediately before deletion.
- Make all mutating tests opt-in and default the verification script to read-only or
