T09 · Insecure Skill Coding Practices
- Location
SKILL.md:33- Finding
User-Provided Classification Count Is Ignored During Bulk Modification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 33–38
Vulnerability Type: Unbounded bulk data modification
Risk Level: MediumVulnerable Code
markdown 4. **Select all videos**: Use `browser.check` to check all matching videos 5. **Submit**: Use `browser.click` to: - Click [Add to structure] - Select the tag - Click ConfirmThe displayed interface labels have been translated into English without changing the meaning of the source instructions.
Technical Analysis
The Skill description states that the user provides both a tag and the number of videos to classify. Its examples also pass explicit limits such as
count=20andcount=200. However, the mandatory workflow does not validate, apply, or enforce this count.Instead, line 33 directs the Agent to select every video matching the filters. Lines 35–38 then direct it to confirm a state-changing classification operation. Consequently, the affected-record scope is determined by the filter result rather than the limit authorized by the user.
The batching recommendation elsewhere in the file does not correct the vulnerability because it is advisory, does not bind the cumulative number of selected records, and does not require verification before submission.
Attack Path
- A user requests classification of a limited number of videos, such as 20.
- The configured filters return more than the requested number.
- The Agent follows the mandatory instruction to select all matching videos.
- The Agent invokes the add-to-structure operation and confirms it.
- Every matching record is modified, exceeding the scope requested by the user.
Exploitation does not grant additional system privileges, but it can cause an authenticated Agent to perform a broader backend mutation than the user authorized.
Impact Assessment
The vulnerability affects the integrity of video classification data in the authenticated bac ...[truncated 513 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse and validate the requested count as a positive integer before accessing the backend.
- Reject missing, invalid, zero, negative, or unreasonably large count values.
- Select exactly the requested number of records rather than using a global select-all action.
- If pagination is required, track the cumulative selection count across pages and stop when the requested limit is reached.
- Before submission, compare the selected-record count with the user-requested count and abort on any mismatch.
- Show the final tag, filter criteria, and affected-record count and obtain explicit confirmation before performing the bulk mutation.
- Process large requests in bounded batches while ensuring that the cumulative total never exceeds the authorized count.
- Record the affected record identifiers or preserve an audit log so unintended changes can be identified and reversed.
