T09 · Insecure Skill Coding Practices
- Location
scripts/graph.sh:34- Finding
Tier-3 Exact-Name Confirmation Is Not Validated
- Content
View full analysis
Vulnerability Details
File Location:
scripts/graph.sh:34-42, 123-126
Vulnerability Type: Confirmation control bypass
Risk Level: MediumVulnerable Code
bash --confirm-name) [[ $# -ge 2 && -n "$2" ]] || { echo "ERROR: --confirm-name requires the exact object name." >&2 exit 2 } CONFIRM_NAME="$2" shift 2 ;;bash if (( TIER == 3 )) && [[ -z "$CONFIRM_NAME" ]]; then echo "ERROR: Tier 3 action refused. Re-run with --confirm-name and the exact user-confirmed object name." >&2 exit 7 fiTechnical Analysis
The wrapper claims to enforce exact-name confirmation for Tier-3 operations, including device wipe, device retirement, Activation Lock bypass, managed-device deletion, Autopilot identity deletion, and Conditional Access policy deletion.
However,
--confirm-nameaccepts any non-empty string. The later authorization check only verifies thatCONFIRM_NAMEis not empty; it does not retrieve the target object's canonical name or serial number and does not compare that identifier with the supplied value.Consequently, a value such as
--confirm-name xsatisfies the wrapper's Tier-3 check. The confirmation is also not cryptographically or logically bound to the HTTP method, endpoint, or target object ID.Attack Path
-
An attacker, compromised agent, or incorrectly instructed agent selects an allowed Tier-3 Graph endpoint.
-
It invokes
scripts/graph.shwith the destructive method and target object ID. -
It supplies any arbitrary non-empty confirmation value, for example:
bash scripts/graph.sh --confirm-name "x" POST \ "/deviceManagement/managedDevices/{id}/wipe" -
The non-empty check succeeds even though
"x"is not the target device's name. -
If the configured Microsoft Graph application has the required permission, the wrapper sends the destructive request.
Impact Assessment
Successful exploitation can bypass the Skill's principal safety control for destructive a ...[truncated 734 chars]
-
- Remediation
View remediation
Remediation Suggestions
- Resolve the target object with a permitted
GETrequest before executing a Tier-3 operation. - Extract its canonical confirmation identifier:
- Device name for wipe, retire, managed-device deletion, and Activation Lock bypass.
- Serial number for Autopilot identity deletion.
- Display name for Conditional Access policy deletion.
- Compare the supplied confirmation with that canonical identifier using an exact, case-sensitive comparison unless a clearly documented normalization rule is required.
- Refuse execution when the object cannot be retrieved, the identifier is absent, or the supplied value differs.
- Bind confirmation to the exact action and target. A stronger design would issue a short-lived confirmation artifact derived from:
- HTTP method,
- normalized endpoint,
- target object ID,
- canonical object name,
- expiration time.
- Avoid relying solely on an agent-provided assertion that the user confirmed the name.
- Add automated tests proving that empty, incorrect, stale, and unrelated names are rejected for every Tier-3 endpoint.
- Continue enforcing least-privilege Microsoft Graph permissions and use
INTUNE_READ_ONLY=truefor reporting-only deployments.
- Resolve the target object with a permitted
