T09 · Insecure Skill Coding Practices
- Location
scripts/bundle.cjs:83765- Finding
Bulk outbound calls can execute without programmatic confirmation
- Content
View full analysis
validSet.has(c.phoneNumber) ); const result = await executeOutboundCallFlow( valid, options.instanceId, options.scriptId, taskInput.scenarioDescription, taskInput.agentProfile, validContacts ); return { taskInput, jobGroupId: result.jobGroupId, instanceId: result.instanceId, scriptId: result.scriptId, totalPhones: valid.length }; } catch (error) { console.error(` \u274C \u4EFB\u52A1\u6267\u884C\u5931\u8D25: ${error.message} `); throw error; } } ``` The called flow starts the external operation directly: ```javascript console.log("\n6. \u542F\u52A8\u5916\u547C\u4EFB\u52A1..."); await client.startJobGroup(jobGroupId, phoneNumbers, contacts); ``` The documentation states that explicit user confirmation is mandatory, but the executable does not enforc ...[truncated 2801 chars]- Remediation
View remediation
` before any cloud mutation or call initiation. 5. Reject expired tokens and reject approval if any task field changes after confirmation. 6. Place the authorization check immediately before instance creation, script creation, contact assignment, and `startJobGroup`, rather than relying solely on Agent instructions. 7. Add configurable limits for maximum contacts per task, maximum daily calls, concurrency, and estimated cost. 8. Require a separately configured automation policy before allowing `--no-interactive`. 9. Record an audit event containing the approving identity, task hash, timestamp, contact count, and resulting job-group ID. 10. Use least-privilege Alibaba Cloud credentials restricted to only the necessary OutboundBot operations and resources. ]]>
