T09 · Insecure Skill Coding Practices
- Location
SKILL.md:15- Finding
Database Index Changes May Execute Without Explicit User Approval
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15-18, 89-99, and 110-115
Vulnerability Type: Unsafe default authorization for schema-changing database operations
Risk Level: HighVulnerable Code Snippets
Faithful English translation of
SKILL.md, lines 15-18:markdown - Execution confirmation mode (optional): - Not specified: `No-confirmation mode` (default; index creation/deletion can be executed directly without waiting for user confirmation) - Specified: `Confirmation-required mode` (user confirmation is required before creating/deleting indexes)Faithful English translation of
SKILL.md, lines 89-99:markdown ### 4) Provide justification before changes Before creating/deleting an index, output: 1. Change type. 2. Change justification. 3. Risk assessment. 4. Statement to execute. Proceed according to the execution confirmation mode: - `Confirmation-required mode`: only proceed after explicit user confirmation. - `No-confirmation mode`: proceed directly without waiting for user confirmation.Faithful English translation of
SKILL.md, lines 110-115:markdown ### 5) Execute index changes and run EXPLAIN 1. SQL databases: write DDL to the index-optimization SQL file. 2. MongoDB: output createIndex and corresponding dropIndex rollback statements. 3. Run EXPLAIN before and after the index changes. 4. Record whether the target index is used. 5. For removal of an old index, validate the replacement before executing deletion.Technical Analysis
The Skill makes no-confirmation execution the default and explicitly permits immediate index creation or deletion. These are schema-changing operations with material availability and performance consequences. A rollback statement and EXPLAIN validation reduce operational risk but do not constitute authorization.
The behavior also conflicts with
agents/openai.yaml:4, whose default prompt ...[truncated 2185 chars]- Remediation
View remediation
Remediation Suggestions
- Make
Confirmation-required modethe default whenever no mode is specified. - Require explicit, operation-specific approval immediately before every schema-changing statement is executed.
- Present the exact target database, environment, table or collection, index name, DDL statement, expected locking behavior, and rollback statement in the approval request.
- Never automatically execute index deletion. Treat every proposed removal as advisory until separately approved.
- Restrict automatic execution, if retained at all, to an explicitly selected non-production environment and reject ambiguous environment configurations.
- Use a read-only database account for discovery and EXPLAIN stages. Acquire narrowly scoped DDL capability only after approval.
- Validate replacement indexes against representative production workload evidence, database index-usage statistics, and before-and-after execution plans rather than repository search results alone.
- Add database-native safeguards where available, such as online DDL options, lock timeouts, maintenance windows, and monitoring with automatic abort thresholds.
- Reconcile
SKILL.mdwithagents/openai.yamlso both consistently require confirmation. - Record an immutable audit entry containing the approver, target environment, exact operation, execution result, and rollback status.
- Make
