T09 · Insecure Skill Coding Practices
- Location
scripts/guard.js:47- Finding
Non-Atomic Check-and-Record Workflow Permits Duplicate Irreversible Actions
- Content
View full analysis
a.type === type && a.target === target); if (direct) { console.error(`DUPLICATE: Already performed ${type} on ${target}`); console.error(` Date: ${direct.ts}`); if (direct.note) console.error(` Note: ${direct.note}`); process.exit(1); } // Parent match — already acted on this parent (catches reply-to-same-post) const parentMatch = actions.find(a => a.type === type && a.parent === target); if (parentMatch) { console.error(`DUPLICATE: Already performed ${type} on parent ${target}`); console.error(` Via: ${parentMatch.target}`); console.error(` Date: ${parentMatch.ts}`); if (parentMatch.note) console.error(` Note: ${parentMatch.note}`); process.exit(1); } console.log(`OK: No prior ${type} on ${target}`); process.exit(0); } // Record an action function record(type, target) { const note = getOpt('note') || ''; const parent = getOpt('parent') || undefined; const action = { type, target, ...(parent && { parent }), ...(note && { note }), ts: new Date().toISOString(), }; appendAction(action); console.log(`RECORDED: ${type} ${target}${parent ? ' (parent: ' + parent + ')' : ''}`); } ``` The documented calling pattern separates checking, performing the external operation, and recording: ```text BEFORE each action: node guard.js check If exit 1 → SKIP (already done) DO the action AFTER success: node guard.js record --note "what you did" --parent ``` ### Technical Analysis Deduplication is implemente ...[truncated 1806 chars]- Remediation
View remediation
