T09 · Insecure Skill Coding Practices
- Location
scripts/triage.sh:94- Finding
Command Execution Through Unvalidated Bash Arithmetic Input
- Content
View full analysis
- Remediation
View remediation
&2 exit 2 fi } validate_uint "FLEET_PR_STALE_DAYS" "$STALE_DAYS" validate_uint "FLEET_PR_CI_WEIGHT" "$CI_WEIGHT" validate_uint "FLEET_PR_MAX_PRS" "$MAX_PRS" ``` After syntax validation, enforce sensible bounds to prevent denial-of-service or unintended behavior: ```bash if (( STALE_DAYS > 3650 )); then echo "Error: FLEET_PR_STALE_DAYS is outside the permitted range." >&2 exit 2 fi if (( MAX_PRS < 1 || MAX_PRS > 1000 )); then echo "Error: FLEET_PR_MAX_PRS must be between 1 and 1000." >&2 exit 2 fi ``` Additional hardening measures: 1. Validate configuration immediately after reading the environment and before invoking `date`, `gh`, or any arithmetic comparison. 2. Reject malformed values rather than attempting to normalize or evaluate them. 3. Apply the same numeric-validation policy to every current and future environment-controlled arithmetic value. 4. In CI and agent deployments, use an explicit environment allowlist and avoid forwarding untrusted environment variables to the Skill. 5. Add regression tests using malformed arithmetic strings and array-subscript payloads to verify that validation rejects them before PR processing begins. ]]>
