T09 · Insecure Skill Coding Practices
- Location
index.ts:1- Finding
Advertised tool policy enforcement is not integrated into the execution path
- Content
View full analysis
, rules: PolicyRules, ): PolicyResult { if (rules.blockedTools?.includes(toolName)) { return { allowed: false, reason: `tool "${toolName}" blocked by agent policy` }; } if (rules.restrictedTools?.includes(toolName)) { return { allowed: false, reason: `tool "${toolName}" restricted by agent policy` }; } return { allowed: true }; } ``` ### Technical Analysis The project advertises enforcement of `blockedTools` and `restrictedTools`, and the configuration schema accepts `policyRules`. However, neither plugin entry point imports or invokes `evaluatePolicy()`. The registered hooks also never read `policyRules` or register a pre-tool-execution control. Consequently, the policy implementation is dead code rather than an active security boundary. A configured blocked tool remains executable. The documented behavior for restricted tools is also inconsistent with the implementation: the README states that restricted tools wait for operator confirmation, while `evaluatePolicy()` only returns an unc ...[truncated 1243 chars]- Remediation
View remediation
