T09 · Insecure Skill Coding Practices
- Location
SKILL.md:2342- Finding
Unauthenticated Webhook Can Trigger Privileged Financial Containment
- Content
View full analysis
= 95: anomaly = AnomalyResult( detected=True, signal="budget_exhaustion", severity="critical", agent_id=agent_id, details=payload, ) responder.auto_contain(agent_id, anomaly) elif utilization >= 80: responder.oncall_callback( severity="WARNING", message=f"Budget at {utilization}% for {agent_id}", ) elif event_type == "reputation_change": score_delta = float(payload.get("score_delta", 0)) if score_delta < -0.15: anomaly = AnomalyResult( detected=True, signal="reputation_drift", severity="critical" if score_delta < -0.30 else "warning", agent_id=agent_id, details=payload, ) responder.escalate( agent_id, anomaly, EscalationTier.AUTO_CONTAIN if score_delta < -0.30 else EscalationTier.ALERT_HUMAN, ) return jsonify({"status": "processed"}) ``` ### Technical Analysis The webhook endpoint accepts an arbitrary JSON request and trusts its `event_type`, `agent_id`, and `payload` fields without authenticating the sender. It does not verify a GreenHelix web ...[truncated 2364 chars]- Remediation
View remediation
