T09 · Insecure Skill Coding Practices
- Location
scripts/identifier.py:366- Finding
Unconfirmed Expense Reports Can Automatically Create and Enrich Client Records
- Content
View full analysis
Vulnerability Details
File Location:
scripts/identifier.py, lines 366-375
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: MediumVulnerable Code
python if company: slug, method = match_side(company, clients) is_new = False if not slug: slug = slugify(company) _, is_new = upsert_client(clients, slug, company, "auto-from-note-de-frais", siren=siren, sources=["note-de-frais"]) if is_new: for c in clients: if c["slug"] == slug: c["aValider"] = TrueTechnical Analysis
The implementation treats the
companyandsiren_foundfields extracted from an expense report as sufficiently trustworthy to create a persistent client record. This behavior conflicts with the documented trust boundary inSKILL.md, which states that automatic client creation is limited to a confirmed bank-statement holder.Marking the record with
aValiderdoes not prevent the record or its SIRENs from being saved and used by subsequent identification operations. An incorrectly extracted or attacker-influenced company identity can therefore become part of the authoritative client registry before human confirmation.Attack Path
- An attacker or malformed document supplies an expense report containing a crafted company name and SIREN.
- The upstream analysis places these values in
analyse.fields.companyandanalyse.fields.siren_found. - The company name does not match an existing client.
slugify()generates a new identifier, andupsert_client()immediately inserts the company and SIREN intoclients.json.- Later documents can match the injected record by company name or SIREN.
- The poisoned identity may consequently influence later document attribution.
Impact Assessment
Exploitation does not grant operating-system privileges or arbitrary ...[truncated 269 chars]
- Remediation
View remediation
Remediation Suggestions
- Restrict automatic client creation to the sources explicitly documented as authoritative.
- Return
needs_review: truewhen an expense report references an unknown company. - Do not persist
company, SIREN, IBAN, or domain information until a human explicitly confirms the client. - Store pending suggestions separately from the authoritative
clients.jsonregistry. - Validate that a SIREN is side-specific and belongs to the identified company before adding it.
- Add tests proving that an unknown expense-report company cannot modify the authoritative registry without confirmation.
