T09 · Insecure Skill Coding Practices
- Location
run.sh:75- Finding
Destructive worktree removal bypasses confirmation in non-interactive environments
- Content
View full analysis
/dev/null && \ echo "Banco $DB removido." fi if [ -d "$WORKTREE_PATH" ]; then git worktree remove "$WORKTREE_PATH" --force 2>/dev/null || rm -rf "$WORKTREE_PATH" git worktree prune echo "Worktree removido: $WORKTREE_PATH" else echo "Worktree não encontrado: $WORKTREE_PATH" fi if [ -f "$ENV_FILE" ]; then rm "$ENV_FILE" echo "Env removido: $ENV_FILE" fi ``` ### Technical Analysis `confirm_destructive` only requests confirmation when standard input is attached to a terminal. If `[ -t 0 ]` is false, the function reaches its end and implicitly returns success. Consequently, non-interactive execution bypasses confirmation rather than failing closed. This behavior conflicts with the documented requirement ...[truncated 1628 chars]- Remediation
View remediation
