T09 · Insecure Skill Coding Practices
- Location
health_monitor.py:156- Finding
Unsafe Broad Process Termination in Automatic RAM Remediation
- Content
View full analysis
5: # Only kill processes using >5% RAM # Try graceful first os.kill(pid, 15) # SIGTERM time.sleep(1) try: os.kill(pid, 9) # SIGKILL except: pass killed.append(f"{proc['cmd'][:30]} (PID:{pid})") except: pass return killed ``` ### Technical Analysis The remediation function selects processes from the five highest RAM consumers and terminates every selected process using more than 5% of system memory unless its command text contains one of several protected substrings. The protection mechanism is not a reliable process-authorization control: - It relies on substring matching against command text rather than verified process identity. - It does not protect databases, application servers, monitoring agents, user sessions, or other essential services. - It does not verify process ownership, cgroup membership, service role, or parent-child relationships. - It does not require RAM usage to have reached the configured critical threshold. - It sends `SIGKILL` after a fixed one-second delay without first checking whether `SIGTERM` succeeded. - It obtains the PID from a prior process listing without revalidating process identity, creating a potential PID-reuse race. Consequen ...[truncated 1689 chars]- Remediation
View remediation
