T09 · Insecure Skill Coding Practices
- Location
scripts/cron-manager.sh:83- Finding
Untrusted PID File Can Cause Termination of Unrelated Processes
- Content
View full analysis
/dev/null 2>&1; then kill $pid echo "Monitoring stopped (PID: $pid)" else echo "Monitor process does not exist" fi rm "$PID_FILE" ``` ### Technical Analysis The `stop_monitor` function trusts the contents of the project-local `.monitor.pid` file without validating that the value: - Is a single positive integer. - Identifies a process started by this Skill. - Belongs to the expected monitoring command. - Has not become stale and been reassigned to another process. The value is also passed to `ps` and `kill` without quoting or an option terminator. Because `.monitor.pid` is stored in the working project directory, any user or process able to modify project files can replace its content. Even a syntactically valid PID can identify an unrelated process. PID reuse can produce the same result without deliberate tampering: after the original monitor exits, the operating system may assign its PID to another process while the stale PID file remains. ### Attack Path 1. The Skill creates `.monitor.pid` in the project directory. 2. An attacker or untrusted project process replaces its contents with the PID of another process owned by the victim. 3. The victim or Agent invokes: ```bash ./scripts/main.sh stop ``` or: ```bash ./scripts/main.sh restart ``` 4. `ps` confirms that the attacker-selected PID exists. 5. `kill` sends the default termination signal to that unrelated process. ### Impact Assessment An attacker can terminate processes that the current user is authorized to signal. This may interrupt editors, build jobs, local services, Agent processes, or other user workloads. The flaw does n ...[truncated 124 chars]- Remediation
View remediation
