T09 · Insecure Skill Coding Practices
- Location
scripts/obs_lifecycle_analyzer.py:380- Finding
Mutating lifecycle operations allow confirmation bypass through --apply
- Content
View full analysis
Vulnerability Details
File Location:
scripts/obs_lifecycle_analyzer.py:380-383, 425-427, 514-516, 526-532, 582-583
Vulnerability Type: Unenforced authorization and confirmation gate
Risk Level: HighVulnerable Code
python def _confirm(message: str, apply: bool) -> None: if apply: print(f"[confirm-gate] SKIPPED (--apply provided; user confirmation assumed given elsewhere): {message}") return print(f"\n⚠️ {message}") answer = input("Type 'yes' to continue, anything else to abort: ").strip().lower() if answer != "yes": sys.exit("Aborted by user.")The mutation paths rely on this function immediately before changing the remote lifecycle configuration:
python _confirm( f"PUT will REPLACE the whole lifecycle configuration of {bucket} " f"with {len(new_cfg['Rules'])} rule(s). Preview showed " f"{pv['affected_objects']} affected object(s). Proceed?", apply, ) _put_config(bucket, new_cfg)python _confirm( f"Updating rule '{rule_id}' of {bucket}. Preview: " f"{pv['affected_objects']} object(s), {pv['affected_size_gb']} GB " f"would be affected by the updated rule. Proceed?", apply, ) _put_config(bucket, cfg)python _confirm( f"Deleting rule '{rule_id}' from {bucket} is IRREVERSIBLE. " f"{len(rules) - len(remaining)} rule(s) will be removed, " f"{len(remaining)} kept. Proceed?", apply, ) if remaining: _put_config(bucket, {"Rules": remaining}) else: _delete_config(bucket)The bypass is exposed directly through the command-line interface:
python p.add_argument( "--apply", action="store_true", help="skip the interactive confirmation " "(only after user confirmation was given elsewhere)", )Technical Analysis
The Skill states that lifecycle creation, update, and deletion require preview and explicit user confirmation. The executable implementation does not enforce evidence of that authorizati ...[truncated 2419 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
--applyfrom direct mutation commands where interactive approval is required. - For automation, introduce a short-lived approval artifact generated only after showing:
- The target bucket.
- The exact operation.
- The immutable final lifecycle JSON.
- The affected-object preview.
- Bind the approval artifact to a digest of the bucket, operation, rule configuration, and preview result. Reject it if any value changes.
- Expire approval artifacts after a short interval and prevent reuse.
- Separate planning and application:
planproduces the final configuration and digest.- The user approves that digest.
applyaccepts only the approved, unchanged plan.
- Require a stronger confirmation for whole-configuration deletion and broad expiration rules.
- Add tests proving that mutation cannot reach
_put_config()or_delete_config()without a valid approval artifact.
- Remove
