T09 · Insecure Skill Coding Practices
- Location
scripts/switch-embedding-model.sh:95- Finding
Destructive Vector Database Deletion Lacks Enforced Confirmation and Recoverable Rollback
- Content
View full analysis
Vulnerability Details
File Location:
scripts/switch-embedding-model.sh, lines 95–126 and 177–181
Vulnerability Type: Destructive operation without an enforced confirmation or data rollback mechanism
Risk Level: HighVulnerable Code
bash # ── Step 3: Modify ov.conf ── echo "" echo "[3/6] Modifying ov.conf..." # BUG-5 fix: backup original config for rollback cp "${SANDBOX_DIR}/process_dir/ov.conf" "${SANDBOX_DIR}/process_dir/ov.conf.bak" python3 -c " import json conf_path = '${SANDBOX_DIR}/process_dir/ov.conf' with open(conf_path, encoding='utf-8') as f: data = json.load(f) dense = data['embedding']['dense'] dense['provider'] = 'openai' dense['model'] = '${MODEL_NAME}' dense['api_key'] = 'not-needed' dense['api_base'] = 'http://127.0.0.1:${LLAMA_PORT}/v1' dense['dimension'] = ${TARGET_DIMENSION} with open(conf_path, 'w', encoding='utf-8') as f: json.dump(data, f, indent=2, ensure_ascii=False) print(' ov.conf updated (backup at ov.conf.bak)') " # ── Step 4: Delete incompatible vectordb index ── echo "" echo "[4/6] Checking vectordb index compatibility..." COLLECTION_META="${SANDBOX_DIR}/data/vectordb/context/collection_meta.json" if [ -f "$COLLECTION_META" ]; then CURRENT_DIM=$(python3 -c "import json; print(json.load(open('$COLLECTION_META'))['Dimension'])") if [ "$CURRENT_DIM" != "$TARGET_DIMENSION" ]; then echo " Dimension mismatch: $CURRENT_DIM → $TARGET_DIMENSION" echo " Deleting vectordb/context..." rm -rf "${SANDBOX_DIR}/data/vectordb/context" echo " Deleted." else echo " Dimensions match ($CURRENT_DIM), no deletion needed." fi else echo " No existing collection_meta.json, skipping." fiThe failure rollback restores only the configuration:
bash if [ "$HEALTHY" != "True" ]; then echo " ❌ Server not healthy after ${HEALTH_TIMEOUT}s" echo " Rolling back config..." cp "${SANDBOX_DIR}/process_dir/ov.conf.bak" "${SANDBOX_DIR}/process_dir/ov.conf" echo " Check log: ${SANDB ...[truncated 2576 chars]- Remediation
View remediation
Remediation Suggestions
- Require an explicit option such as
--confirm-delete-indexbefore deleting the database context. Fail closed when it is absent. - In interactive operation, display the existing dimension, measured target dimension, exact directory, and deletion consequences before requesting confirmation.
- Add a
--dry-runmode that reports all planned configuration, process, and filesystem changes. - Replace immediate deletion with an atomic rename, for example:
bash mv "${SANDBOX_DIR}/data/vectordb/context" \ "${SANDBOX_DIR}/data/vectordb/context.backup.$(date +%s)" - Restore the preserved directory on every failure path, including failed execution, failed health checks, unchanged PID, dimension mismatch, and detected startup errors.
- Delete the preserved directory only after the new server, PID, collection dimension, and logs have all passed verification.
- Validate that
SANDBOX_DIRis non-empty, canonical, and constrained to the expected OpenViking sandbox root before any recursive filesystem operation. - Document whether the vector store is reproducible from authoritative source data and require a separate backup when it is not.
- Require an explicit option such as
