T09 · Insecure Skill Coding Practices
- Location
references/workflow-variants.md:37- Finding
Quick Mode Explicitly Disables Security Review
- Content
View full analysis
Vulnerability Details
File Location:
references/workflow-variants.md:37-51
Vulnerability Type: Security review bypass caused by unsafe workflow configuration
Risk Level: MediumVulnerable Code Snippet
markdown ## Variant: quick(快速开发) - Review 快速(只检查逻辑正确性和 Plan 一致性,跳过安全和风格) - 适用: 单文件功能、简单脚本、工具类小功能 ### 触发 - 用户说"快速开发"/"简单开发"/"小功能" - Assess 阶段判定复杂度为"简单" - 用户说"不用太正式"The relevant statement translates to: “The quick review checks only logical correctness and Plan consistency, skipping security and style.”
Technical Analysis
Quick mode explicitly instructs the Reviewer to omit security checks. It may be activated by ordinary user wording or automatically when the assessment classifies a task as simple.
Task complexity and file count are not reliable indicators of security risk. A single-file script or small utility may still contain command injection, path traversal, authorization failures, exposed credentials, unsafe deserialization, or improper input validation. Consequently, this workflow can mark an implementation as reviewed even though no security analysis occurred.
This behavior conflicts with the security controls defined in
references/review-checklist.md:83-88, which require checks for injection, secret exposure, path traversal, input validation, and authorization.Attack Path
- A user requests quick or informal development, or the agent classifies the task as simple.
- The skill selects the quick workflow.
- The Developer produces code containing a security flaw, whether accidentally or through attacker-controlled requirements or inputs.
- The Reviewer checks only logical correctness and Plan consistency.
- The security flaw is not examined because the workflow explicitly excludes security review.
- The implementation proceeds to the final report and may be presented as reviewed.
- If deployed or executed, an attacker may exploit the omitted flaw according to the affected implementation’s runtime privil ...[truncated 627 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the instruction to skip security review in quick mode.
- Define a mandatory security baseline for every workflow variant, including checks for:
- Command, SQL, template, and cross-site scripting injection
- Hardcoded or logged credentials, tokens, and other secrets
- Path traversal and unsafe file operations
- Input validation and output encoding
- Authentication and authorization enforcement
- Unsafe dependency additions
- Allow quick mode to reduce review depth or style analysis, but never eliminate security coverage.
- Require escalation to the standard or strict workflow when code handles credentials, untrusted input, filesystem access, command execution, network services, authentication, authorization, payment data, or other sensitive operations.
- Ensure the final report distinguishes between a baseline review and a full security review so users do not receive a misleading assurance.
- Add regression tests or workflow assertions verifying that every review variant includes the mandatory security checklist.
