T09 · Insecure Skill Coding Practices
- Location
scripts/budget-check.py:62- Finding
Invalid numeric values can bypass budget controls
- Content
View full analysis
0 else 0 if new_usage_rate >= 100: status = 'red' action = '🔴 拦截,需升级审批' elif new_usage_rate >= threshold: status = 'yellow' action = '🟡 通知负责人,允许通过' else: status = 'green' action = '🟢 自动通过' ``` The affected values originate from unvalidated floating-point conversions: ```python float(args.amount) ``` ```python float(row.get('金额', 0)) ``` ### Technical Analysis The application converts user-controlled values with `float()` but does not verify that they are finite, positive, and within an acceptable range. Python accepts special values such as `nan`, `inf`, and `-inf`. If `amount` is `nan`, `new_usage_rate` also becomes `nan`. Comparisons involving `nan` are false, so both the red and yellow conditions fail and execution reaches the green branch. Negative expense amounts can similarly reduce the computed utilization rate. Budget totals also lack validation. When `total` is zero or negative, the conditional expression assigns a utilization rate of zero, causing the request to be treated as green unless a negative threshold was configured. This is fail-open behavior in a financial control decision. ### Attack Path 1. An attacker or untrusted data source supplies a request using `--amount nan`, or inserts `nan` into the amount column of a batch CSV. 2. `float()` accepts the value without raising an exception. 3. The utilization calculation produces `nan`. 4. Both `new_usage_rate >= 100` and `new_usage_rate >= threshold` evaluate to false. 5. The application returns a ...[truncated 801 chars]- Remediation
View remediation
0 else 0` fallback with explicit rejection. Invalid budget configuration must fail closed rather than result in green approval. 6. Return a dedicated validation-error status that downstream systems cannot interpret as approval. 7. Add automated tests for `nan`, positive and negative infinity, zero, negative amounts, negative budgets, extremely large values, and malformed numeric strings. ]]>
