T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Destructive sandbox cleanup lacks enforced confirmation, dry-run, and path constraints
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:24-41
Equivalent duplicated instructions:sop-dev-002-cleanup-post-sandbox.yaml:13-41
Vulnerability Type: Unprotected destructive cleanup operations
Risk Level: HighVulnerable Instructions
markdown 1. **Identificar artifacts a preservar** — Revisar ARTIFACTS listados en COMMS del bloque SANDBOX_VALIDATED. Estos NO se borran (se promueven a host si procede). 2. **Eliminar archivos temporales** — Borrar del sandbox: - Archivos `*.tmp`, `*.temp`, `*.bak`, `*~` - Directorios `__pycache__/`, `.pytest_cache/`, `node_modules/` (si no son artifacts) - Logs de ejecución temporal (`*.log`, `nohup.out`) - Cualquier archivo creado durante validación que no esté en ARTIFACTS 3. **Reset de estado de servicios** — Si se levantaron servicios en sandbox (DB, Redis, mocks): - Detener contenedores/servicios: `docker compose down` o equivalente - Limpiar volúmenes temporales si se crearon - Verificar que puertos quedan libres 4. **Reset de git (si aplica)** — Si se hizo `git clone` o trabajo en repo: - `git checkout -- .` para descartar cambios no committed - `git clean -fd` para eliminar untracked (excepto artifacts preservados) - Volver al commit/branch base documentado en SOP-DEV-001 5. **Verificar limpieza** — Ejecutar `ls -la` y `git status` en sandbox root. Confirmar que solo quedan artifacts listados y estructura base.Technical Analysis
The Skill instructs the agent to perform irreversible cleanup automatically after a task reaches
SANDBOX_VALIDATEDor is cancelled or aborted. The operations include:- Deleting every validation-created file not listed in
ARTIFACTS. - Running
git checkout -- ., which discards tracked, uncommitted changes. - Running
git clean -fd, which recursively deletes untracked files and directories. - Removing temporary service volumes, potentially destroying database or application state.
The preservation boundary is deriv ...[truncated 2015 chars]
- Deleting every validation-created file not listed in
- Remediation
View remediation
Remediation Suggestions
- Require explicit user confirmation immediately before destructive execution and display the exact files, directories, repository changes, and volumes that will be removed.
- Make a non-destructive preview mandatory:
- Run
git status --short. - Run
git clean -ndbefore anygit clean -fd. - Generate a deletion manifest for non-Git files.
- Run
- Resolve and canonicalize every target path, then verify that it is strictly contained within the designated sandbox root. Reject symlinks or resolved paths escaping that boundary.
- Require a validated preservation manifest rather than treating absence from
ARTIFACTSas authorization to delete. - Back up or stash tracked modifications before
git checkout -- ., and require separate confirmation before discarding them. - Exclude preserved artifacts mechanically from cleanup rather than relying only on prose instructions.
- Require separate, explicit confirmation before deleting service or container volumes, and identify each volume by exact name.
- Abort cleanup when COMMS metadata is missing, malformed, ambiguous, or inconsistent with the filesystem.
- Record the preview, confirmation, resolved sandbox root, and final deletion manifest in the cleanup audit log.
