T09 · Insecure Skill Coding Practices
- Location
scripts/jenkins_cli.py:174- Finding
State-Changing Jenkins Operations Do Not Enforce User Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/jenkins_cli.py, lines 174–183, 204–214, and 228–249
Vulnerability Type: Missing authorization confirmation for state-changing operations
Risk Level: MediumVulnerable Code
python def cmd_build(cfg, args): params = {} for kv in args.param or []: if "=" not in kv: die(f"--param expects KEY=VALUE, got: {kv}") k, v = kv.split("=", 1) params[k] = v if params: path = job_path(args.name) + "/buildWithParameters" resp = request(cfg, "POST", path, expect_json=False, params=params) else: path = job_path(args.name) + "/build" resp = request(cfg, "POST", path, expect_json=False) out({"job": args.name, "queued": True, "queue_url": resp.headers.get("Location")})python def cmd_enable(cfg, args): request(cfg, "POST", job_path(args.name) + "/enable", expect_json=False) out({"job": args.name, "enabled": True}) def cmd_disable(cfg, args): request(cfg, "POST", job_path(args.name) + "/disable", expect_json=False) out({"job": args.name, "disabled": True})python s = sub.add_parser("build", help="trigger a build") s.add_argument("name") s.add_argument("--param", action="append", help="KEY=VALUE (repeatable)") s.set_defaults(func=cmd_build) ... s = sub.add_parser("enable", help="enable a job") s.add_argument("name") s.set_defaults(func=cmd_enable) s = sub.add_parser("disable", help="disable a job") s.add_argument("name") s.set_defaults(func=cmd_disable)Technical Analysis
The
build,enable, anddisablecommands issue authenticated Jenkins POST requests immediately after parsing their arguments. They do not require an explicit confirmation flag, an interactive confirmation prompt, a dry-run step, or an approval token bound to the selected job and parameters.SKILL.mdinstructs ...[truncated 2262 chars]- Remediation
View remediation
Remediation Suggestions
- Require an explicit confirmation control for every state-changing command, such as
--confirm. - Before confirmation, display the exact Jenkins URL, operation, normalized job name, and complete build parameter set.
- In interactive use, prompt for approval and default to rejection. Do not treat empty input as approval.
- For Agent or non-interactive execution, use a short-lived approval value bound to the exact operation, job, and parameters rather than a reusable global switch.
- Provide a
--dry-runmode that reports the intended request without sending it. - Consider an allowlist for approved jobs or environments, particularly where the configured account can access production pipelines.
- Use separate least-privilege Jenkins tokens for read-only inspection, build triggering, and job configuration so that routine status checks cannot exercise unnecessary mutation privileges.
- Require an explicit confirmation control for every state-changing command, such as
