T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
Destructive ADB Operations May Execute Without Explicit Confirmation
- Content
View full analysis
` parameter to all subsequent commands | ``` The skill then exposes destructive operations without defining any operation-specific confirmation boundary: ```bash # Uninstall while retaining data adb [-s ] shell pm uninstall -k # Complete uninstall adb [-s ] uninstall ``` ```bash adb [-s ] shell pm clear ``` ```bash # Normal reboot adb [-s ] reboot # Reboot into Recovery adb [-s ] reboot recovery # Reboot into Bootloader adb [-s ] reboot bootloader ``` ### Technical Analysis The skill applies a blanket rule that operations should execute immediately whenever exactly one Android device is connected. It does not distinguish read-only diagnostics from state-changing or destructive commands. Commands such as `pm clear`, complete package removal, and device reboot can cause irreversible data loss or operational disruption. Device count is not an adequate authorization mechanism: detecting one device identifies a target but does not establish that the user has approved the exact destructive action. This is an insecure skill configuration because the workflow omits an explicit confi ...[truncated 1408 chars]- Remediation
View remediation
