T09 · Insecure Skill Coding Practices
- Location
SKILL.md:78- Finding
Unvalidated daemon data evaluated as a Bash arithmetic expression
- Content
View full analysis
- Remediation
View remediation
= -1000000 && CURRENT_SCORE <= 1000000 && PREVIOUS_SCORE >= -1000000 && PREVIOUS_SCORE <= 1000000 )); then CHANGE=$((CURRENT_SCORE - PREVIOUS_SCORE)) else alert "INVALID_DATA" "Peer score is outside the accepted range" continue fi else alert "INVALID_DATA" "Peer score is not a valid integer" continue fi ``` Additional hardening should include: 1. Validate the JSON schema and value types with `jq` before converting data into shell variables. 2. Reject null, string, floating-point, non-finite, out-of-range, or otherwise malformed scores. 3. Create the watchdog directory and state file with owner-only permissions, such as directory mode `0700` and file mode `0600`. 4. Set `umask 077` before creating configuration, state, or alert files. 5. Verify that the state file is a regular file owned by the expected user and is not a symbolic link before reading or replacing it. 6. Write state through a securely created temporary file in the same directory and atomically rename it into place. 7. Treat all `pilotctl` output as untrusted unless the daemon authenticates its data source and enforces a strict response schema. ]]>
