T09 · Insecure Skill Coding Practices
- Location
scripts/04_start.py:14- Finding
Privileged Installer Can Terminate Unrelated Local Processes
- Content
View full analysis
Vulnerability Details
File Location:
scripts/04_start.py, lines 14–33
Vulnerability Type: Improper process ownership validation
Risk Level: MediumVulnerable code:
python existing_ports = detect_ports_from_system() if len(existing_ports) >= 4: print("[4/5] ⏭️ Already done: service already running, skip start", flush=True) sys.exit(0) # If some ports are occupied (partial old instance), stop them first if len(existing_ports) > 0: print(f"[4/5] 🛑 Stopping existing instance (ports found: {existing_ports})...", flush=True) try: # Kill processes occupying jiuwenswarm ports result = subprocess.run( "ss -tlnp 2>/dev/null | grep -E ':(517[0-9]|1809[0-9]|1900[0-9]|1901[0-9])' | grep -oP 'pid=\\K\\d+' | sort -u", shell=True, capture_output=True, text=True, timeout=5 ) pids = result.stdout.strip().split() for pid in pids: if pid: os.kill(int(pid), 9) # Wait for ports to be released time.sleep(2) except Exception: passTechnical Analysis
Before starting JiuwenSwarm, the script treats any listener in broadly defined numeric port ranges as an existing JiuwenSwarm process. It extracts PIDs from system-wide
ss -tlnpoutput and sends each matching process an unconditionalSIGKILL.The script does not verify:
- The process owner or UID
- The process executable or command line
- Whether the process was created by this Skill
- Whether the PID belongs to a previously recorded JiuwenSwarm process group
- Whether the user approved terminating the process
Consequently, an unrelated service listening on a matching port can be mistaken for JiuwenSwarm. When this installer runs with root or equivalent privileges, it crosses a local user or service boundary by terminating a process that the port-binding user could not otherwise signal.
Thi ...[truncated 1212 chars]
- Remediation
View remediation
Remediation Suggestions
- Record the PID or process-group ID created by the Skill in a root-owned state file and terminate only that recorded instance.
- Before signaling a process, verify its UID, executable path, command line, and expected deployment directory.
- Replace broad port-pattern matching with checks against the exact configured JiuwenSwarm ports.
- If an unexpected process owns a required port, abort startup and report the conflict rather than terminating it.
- Require explicit user confirmation before stopping any process not provably created by the current deployment.
- Prefer graceful shutdown with
SIGTERM, a timeout, and controlled escalation instead of immediately sendingSIGKILL. - Avoid suppressing all exceptions so ownership-validation and shutdown failures remain visible and auditable.
