T09 · Insecure Skill Coding Practices
- Location
scripts/lifecycle.py:20- Finding
Destructive ECS lifecycle operations lack enforced confirmation and resource-scope validation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/lifecycle.py, lines 20–45 and 80–87
Vulnerability Type: Missing authorization safeguards for destructive cloud operations
Risk Level: HighComplete Code Snippet
python def manage_servers(action: str, server_ids: list, region: str = "cn-north-4", reboot_type: str = "SOFT", auth: AuthManager = None): """Manage Flexus L instance lifecycle (start/stop/reboot)""" action = action.lower() if action not in ["start", "stop", "reboot"]: raise ValueError(f"Invalid action: {action}, must be start/stop/reboot") auth = auth or AuthManager() if not auth.is_configured(): raise ValueError("Please set environment variables HW_ACCESS_KEY, HW_SECRET_KEY, HW_SECURITY_TOKEN or provide --ak --sk parameters") client = auth.get_ecs_client(region) server_id_list = [ServerId(id=sid) for sid in server_ids] try: if action == "start": request = BatchStartServersRequest(body=BatchStartServersRequestBody( os_start=BatchStartServersOption(servers=server_id_list))) response = client.batch_start_servers(request) elif action == "stop": request = BatchStopServersRequest(body=BatchStopServersRequestBody( os_stop=BatchStopServersOption(servers=server_id_list))) response = client.batch_stop_servers(request) else: # reboot request = BatchRebootServersRequest(body=BatchRebootServersRequestBody( reboot=BatchRebootSeversOption(servers=server_id_list, type=reboot_type))) response = client.batch_reboot_servers(request)python if not server_ids or action not in ["start", "stop", "reboot"]: print("ERROR: Invalid parameters. Please provide --instance-id") sys.exit(1) auth = AuthManager(ak=ak, sk=sk, security_token=security_token) action_name = "Starting" if action == "start" else "Stopping" if action == "stop" else "Rebooting" pri ...[truncated 2340 chars]- Remediation
View remediation
Remediation Suggestions
-
Require an explicit confirmation artifact for
stopandreboot. Bind it to:- The requested action.
- The complete, normalized instance-ID list.
- The region.
- The reboot type where applicable.
- A short expiration period.
-
Reject destructive operations when the confirmation artifact is absent, expired, or does not match the exact request.
-
Before creating the ECS batch request, query Huawei Config and verify every target ID is a child ECS resource of an
hcss.l-instanceresource. Fail the entire batch if any ID cannot be verified. -
Add a dry-run or operation-preview mode that displays the resolved resources and intended action without modifying them.
-
Separate destructive and non-destructive code paths so direct calls to
manage_servers()cannot bypass confirmation and scope validation. -
Add automated tests proving that:
- Stop and reboot fail without confirmation.
- Confirmation for one target cannot authorize another.
- Confirmation for stop cannot authorize reboot.
- Non-Flexus ECS IDs are rejected.
- Mixed batches containing one unverified ID are rejected.
-
