T09 · Insecure Skill Coding Practices
- Location
references/guard/guard.py:53- Finding
Release authorization can be satisfied by stale or unrelated checklist evidence
- Content
View full analysis
Vulnerability Details
File Location:
references/guard/guard.py:53-80, 164-190
Related Workflow Location:references/checklists/s2.md:21-22, 85-87
Vulnerability Type: Improper authorization validation
Risk Level: HighVulnerable Code
python R14_LINE = re.compile(r"(?:R14|放行|release)", re.IGNORECASE) CHECKED = re.compile(r"\[[xX]\]") EVIDENCE = re.compile( r"(?:\bm\d{4,}\b|https?://|[“”「」『』]|“|\d{1,2}:\d{2}:\d{2})" )python def r14_state(paths): """返回 (有勾, 有带证据的勾)。""" checked = evidenced = False for path in paths: try: with open(path, encoding="utf-8", errors="replace") as fh: for line in fh: if R14_LINE.search(line) and CHECKED.search(line): checked = True if EVIDENCE.search(line): evidenced = True except OSError: continue return checked, evidencedpython paths = find_checklists(project) if not paths: return deny( # ... payload, ) if is_a: checked, evidenced = r14_state(paths) if not checked: return deny( # ... payload, ) if not evidenced: return deny( # ... payload, )The S2 checklist contains two distinct R14 gates:
markdown - [ ] 🛑 R14 放行原句获得 → skill: oss-contribution/references/rules-and-arbitration.md §R14markdown - [ ] 🛑 R14 放行(推送前再次确认) → skill: oss-contribution/references/rules-and-arbitration.md §R14 - [ ] fork → push branch → gh pr create(或直推如有权限)Technical Analysis
The guard searches every
.oss-task/*/CHECKLIST.mdfile and accepts any checked line containing the broad termsR14,放行, orrelease. It then treats a URL, timestamp, quotation mark, ormNNNNtoken on that line as sufficient authorization evidence.The authorization record is not bound to:
- The active task or che ...[truncated 1890 chars]
- Remediation
View remediation
Remediation Suggestions
- Assign every checklist a unique task identifier and require the hook payload or active-task state to identify exactly one checklist.
- Replace keyword matching with a structured, exact gate identifier such as
P9_PRE_PUSH_APPROVAL. - Store authorization in a machine-readable record containing:
- Task identifier.
- Repository and remote URL.
- Branch and target branch.
- Permitted operation.
- Referenced user-message identifier.
- Approval timestamp.
- Validate that the approval applies to the exact
git pushorgh pr createtarget parsed from the command. - Require the dedicated pre-push gate; do not allow the preliminary S2 R14 item to authorize publication.
- Reject multiple active checklists rather than accepting authorization from any matching file.
- Enforce an appropriate freshness or single-use policy and invalidate approval when the target, branch, or relevant diff changes.
- Add regression tests covering stale checklists, unrelated tasks, mismatched repositories, the preliminary S2 gate, and reused approval evidence.
