T09 · Insecure Skill Coding Practices
- Location
scripts/smn_dms_skill.py:33- Finding
State-Changing Cloud Operations Lack an Enforced Confirmation Gate
- Content
View full analysis
Vulnerability Details
File Location:
scripts/smn_dms_skill.py:33-45, 234-259, 291-292
Vulnerability Type: Confirmation bypass for destructive and billable operations
Risk Level: HighComplete Code Snippet
python def run_hcloud(args_list, region, preview=False): cmd = ["hcloud"] + args_list if region: cmd.append("--cli-region=%s" % region) if preview: print("[PREVIEW] " + " ".join(cmd)) return "" try: proc = subprocess.run(cmd, capture_output=True, text=True, timeout=60)python def delete_smn_topic(a): require(a.topic_urn, "topic_urn", sys.argv) print_json(run_hcloud(["SMN", "DeleteTopic", "--topic_urn=%s" % a.topic_urn], a.region, preview=a.preview)) def confirm_smn_subscription(a): require(a.token, "token", sys.argv) args = ["SMN", "ConfirmSubscription", "--token=%s" % a.token] if a.topic_urn: args.append("--topic_urn=%s" % a.topic_urn) if a.endpoint: args.append("--endpoint=%s" % a.endpoint) print_json(run_hcloud(args, a.region, preview=a.preview)) def delete_dms_instance(a): engine = (a.engine or "").lower() require(engine, "engine (kafka|rabbitmq|rocketmq)", sys.argv) validate_engine(engine, sys.argv) service = ENGINE_SERVICE[engine] require(a.instance_id, "instance_id", sys.argv) print_json(run_hcloud([service, "DeleteInstance", "--instance_id=%s" % a.instance_id], a.region, preview=a.preview))python p.add_argument("--preview", action="store_true", help="print the hcloud command without executing it (R2/R1 confirmation)")Technical Analysis
The Skill documentation classifies resource creation and message publication as R2 operations requiring preview and user confirmation, while deletion and subscription confirmation are R1 operations requiring explicit end-to-end approval. The executable entry point does not enforce th ...[truncated 2785 chars]
- Remediation
View remediation
Remediation Suggestions
- Make preview-only behavior the default for every R1 and R2 action. Do not interpret omission of
--previewas authorization to execute. - Separate preview and execution explicitly, such as with an
--executeflag that is rejected unless accompanied by valid confirmation proof. - Generate a short-lived confirmation token from the normalized action name, service, region, resource identifiers, and all operation parameters shown in the preview.
- Require the execution request to present that token and verify that the parameters exactly match the previewed command. Reject changed, missing, expired, or replayed confirmations.
- For R1 operations, require an additional explicit destructive-action acknowledgement bound to the resource identifier and documented impact.
- Consider an interactive confirmation prompt for direct human CLI use, while retaining a cryptographically bound approval mechanism for Agent or automated use.
- Keep R3 read-only actions outside this gate, but maintain a strict allowlist so newly added state-changing operations cannot be misclassified as read-only.
- Add automated tests proving that every R1 and R2 action fails closed when invoked without valid approval, while
--previewnever executeshcloud.
- Make preview-only behavior the default for every R1 and R2 action. Do not interpret omission of
