T09 · Insecure Skill Coding Practices
- Location
agent_concurrency_controller.py:89- Finding
Caller-Controlled Sensitivity Classification Bypasses Confirmation Policy
- Content
View full analysis
PermissionBehavior: """ 权限检查(参考Claude Code checkPermissions模式) 敏感任务需要额外确认: - critical: 外发操作(公众号发布、付款等) - sensitive: 文件覆盖、配置修改 """ log_entry = { 'timestamp': datetime.now().isoformat(), 'task_id': task.task_id, 'agent_type': task.agent_type, 'sensitive_level': task.sensitive_level, 'action': 'check_permissions' } # 默认允许,但记录日志 behavior = PermissionBehavior.ALLOW if task.sensitive_level == "critical": behavior = PermissionBehavior.ASK log_entry['decision'] = 'ASK_USER_CONFIRMATION' elif task.sensitive_level == "sensitive": log_entry['decision'] = 'ALLOW_WITH_LOG' else: log_entry['decision'] = 'ALLOW' self._log_sensitive_operation(log_entry) return behavior ``` The untrusted value enters through the public API at lines 251–276: ```python def spawn_agent_safe( task: str, agent_type: str = "main", runtime: str = "subagent", priority: int = 5, is_concurrency_safe: bool = False, sensitive_level: str = "normal", timeout_seconds: int = 300 ) -> str: task_id = f"{agent_type}-{datetime.now().strftime('%Y%m%d-%H%M%S')}" agent_task = AgentTask( task_id=task_id, agent_type=agent_type, runtime=runtime, priority=priority, is_concurrency_safe=is_concurrency_safe, sensitive_level=sensitive_level, timeout_seconds=timeout_seconds ) ``` ### Technical Analysis The permission decision is based entirely on the caller-supplied `sensitive_level` string. Only the exact value `critical` requires confirmation. The default ...[truncated 2311 chars]- Remediation
View remediation
