T09 · Insecure Skill Coding Practices
- Location
control.sh:32- Finding
Unvalidated PID File Can Cause Termination of an Unrelated Process
- Content
View full analysis
Vulnerability Details
File Location:
control.sh, lines 32-34
Vulnerability Type: Unsafe PID-file handling
Risk Level: Mediumbash PID=$(cat "$PID_FILE") kill $PID rm "$PID_FILE"Technical Analysis
The stop operation treats the contents of
pid/stock-watcher.pidas a trusted process identifier. It does not verify that the value is numeric, confirm that the referenced process belongs to this Skill, or protect the value from being interpreted as an option bykill.PID files can become stale when a process exits unexpectedly. Operating systems may subsequently reuse the same PID for an unrelated process. In that situation, invoking the stop command would send a termination signal to the unrelated process. A malformed value beginning with a hyphen could also be interpreted as an option or process-group selector because the command does not use
kill -- "$PID".Attack Path
- A stale or modified
pid/stock-watcher.pidcontains the PID of another process. - The user invokes
control.sh stop. - The script reads the unvalidated value into
PID. - The script executes
kill $PIDwithout verifying process ownership or identity. - If the caller has permission to signal the referenced process, that unrelated process is terminated.
Impact Assessment
Exploitation does not grant additional operating-system privileges. However, it can terminate an unrelated process that the current user is already authorized to signal, potentially causing denial of service, interrupted work, or loss of unsaved process state. A specially formed negative PID may broaden the effect to a permitted process group, depending on the shell and
killimplementation.- A stale or modified
- Remediation
View remediation
Remediation Suggestions
- Validate the PID with a strict numeric expression before passing it to
kill. - Use
kill -- "$PID"so the value cannot be parsed as an option. - Verify that the process exists with
kill -0 -- "$PID". - Confirm process identity through
/proc/$PID/cmdline, an expected executable path, or another platform-appropriate mechanism. - Detect and safely remove stale PID files instead of assuming that their existence means the monitor is active.
- Reject symbolic links and create the PID file with restrictive permissions.
- Quote all PID expansions.
Example hardening:
bash PID=$(cat "$PID_FILE") || exit 1 case "$PID" in ''|*[!0-9]*) echo "Invalid PID file" exit 1 ;; esac if ! kill -0 -- "$PID" 2>/dev/null; then echo "Removing stale PID file" rm -f -- "$PID_FILE" exit 1 fi if ! tr '\0' ' ' < "/proc/$PID/cmdline" | grep -Fq "$MONITOR_PY"; then echo "PID does not belong to the stock monitor" exit 1 fi kill -- "$PID" rm -f -- "$PID_FILE"- Validate the PID with a strict numeric expression before passing it to
