T09 · Insecure Skill Coding Practices
- Location
scripts/run_preflight.py:13- Finding
Mandatory User-Approval Gate Can Be Explicitly Bypassed
- Content
View full analysis
argparse.Namespace: parser = argparse.ArgumentParser(description="Run preflight checks on a publish packet") parser.add_argument("--packet", required=True, help="Path to packet JSON") parser.add_argument("--write-back", action="store_true", help="Write check results back to packet") parser.add_argument("--json", action="store_true", help="Print JSON report") parser.add_argument("--allow-unapproved", action="store_true", help="Allow pass even when approval.granted=false") return parser.parse_args() ``` ```python def evaluate(packet: dict, require_approval: bool): preflight = packet.get("preflight", {}) approval = packet.get("approval", {}) publish = packet.get("publish", {}) content = packet.get("content", {}) quality = preflight.get("quality_checks", {}) checks = { "deai_checked": bool(preflight.get("deai_checked")), "risk_reviewed": bool(preflight.get("risk_reviewed")), "source_traceable": bool(preflight.get("source_traceable")), "platforms_present": bool(publish.get("platforms", [])), "title_present": bool(content.get("title")), "approval_granted": (not require_approval) or bool(approval.get("granted")), } ``` ```python def main() -> None: args = parse_args() path, packet = load_packet(args.packet) report = evaluate(packet, require_approval=not args.allow_unapproved) ``` ### Technical Analysis The Skill documentation defines explicit user approval as a hard publishing boundary. However, `run_preflight.py` exposes the production command-line option `--allow-unapproved`, which changes `require_approval` to `False`. When this option is supplied, the following expression succeeds regardless of the store ...[truncated 1818 chars]- Remediation
View remediation
