Back to skill

Security audit

sop-dev-002-cleanup-post-sandbox

Security checks for vulnerabilities and agentic risk

Overview

This is a sandbox cleanup SOP, but it authorizes destructive cleanup commands without clear confirmation, dry-run, or containment checks.

Install only if this SOP will be used in disposable, clearly bounded sandboxes. Before running it, require a dry-run or deletion manifest, confirm the exact sandbox root, verify the ARTIFACTS preserve list, and avoid `git checkout -- .`, `git clean -fd`, or volume deletion unless the user has explicitly approved the specific targets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:24
Finding

Destructive sandbox cleanup lacks enforced confirmation, dry-run, and path constraints

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:24-41
Equivalent duplicated instructions: sop-dev-002-cleanup-post-sandbox.yaml:13-41
Vulnerability Type: Unprotected destructive cleanup operations
Risk Level: High

Vulnerable Instructions

markdown
1. **Identificar artifacts a preservar** — Revisar ARTIFACTS listados en COMMS del bloque SANDBOX_VALIDATED. Estos NO se borran (se promueven a host si procede).
2. **Eliminar archivos temporales** — Borrar del sandbox:
   - Archivos `*.tmp`, `*.temp`, `*.bak`, `*~`
   - Directorios `__pycache__/`, `.pytest_cache/`, `node_modules/` (si no son artifacts)
   - Logs de ejecución temporal (`*.log`, `nohup.out`)
   - Cualquier archivo creado durante validación que no esté en ARTIFACTS
3. **Reset de estado de servicios** — Si se levantaron servicios en sandbox (DB, Redis, mocks):
   - Detener contenedores/servicios: `docker compose down` o equivalente
   - Limpiar volúmenes temporales si se crearon
   - Verificar que puertos quedan libres
4. **Reset de git (si aplica)** — Si se hizo `git clone` o trabajo en repo:
   - `git checkout -- .` para descartar cambios no committed
   - `git clean -fd` para eliminar untracked (excepto artifacts preservados)
   - Volver al commit/branch base documentado en SOP-DEV-001
5. **Verificar limpieza** — Ejecutar `ls -la` y `git status` en sandbox root. Confirmar que solo quedan artifacts listados y estructura base.

Technical Analysis

The Skill instructs the agent to perform irreversible cleanup automatically after a task reaches SANDBOX_VALIDATED or is cancelled or aborted. The operations include:

  • Deleting every validation-created file not listed in ARTIFACTS.
  • Running git checkout -- ., which discards tracked, uncommitted changes.
  • Running git clean -fd, which recursively deletes untracked files and directories.
  • Removing temporary service volumes, potentially destroying database or application state.

The preservation boundary is deriv ...[truncated 2015 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit user confirmation immediately before destructive execution and display the exact files, directories, repository changes, and volumes that will be removed.
  2. Make a non-destructive preview mandatory:
    • Run git status --short.
    • Run git clean -nd before any git clean -fd.
    • Generate a deletion manifest for non-Git files.
  3. Resolve and canonicalize every target path, then verify that it is strictly contained within the designated sandbox root. Reject symlinks or resolved paths escaping that boundary.
  4. Require a validated preservation manifest rather than treating absence from ARTIFACTS as authorization to delete.
  5. Back up or stash tracked modifications before git checkout -- ., and require separate confirmation before discarding them.
  6. Exclude preserved artifacts mechanically from cleanup rather than relying only on prose instructions.
  7. Require separate, explicit confirmation before deleting service or container volumes, and identify each volume by exact name.
  8. Abort cleanup when COMMS metadata is missing, malformed, ambiguous, or inconsistent with the filesystem.
  9. Record the preview, confirmation, resolved sandbox root, and final deletion manifest in the cleanup audit log.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This SOP directs destructive actions such as deleting files, cleaning untracked content, and resetting git state, but it does not require an explicit confirmation step, dry-run, scope validation, or data-loss warning before execution. In context, this is an operational cleanup procedure for a sandbox, which makes the behavior expected, but it is still risky because mis-scoping the sandbox root or artifact list could erase needed data or destroy evidence from the prior task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written only in Spanish ("Descripción de SOP: dev") with no indication that the skill is intended specifically for Spanish-speaking users or a Spanish-only environment. The policy requires avoiding language or locale constraints unless the user is given a choice or the restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description, title, and body text are entirely in Spanish, which imposes a specific language on users and operators. The file does not indicate that Spanish is optional, user-selected, or required for a documented regional or compliance reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.