T09 · Insecure Skill Coding Practices
- Location
scripts/check_lab_artifacts.py:20- Finding
Safety Validator Can Approve Artifacts Containing Dangerous Robot or Network Commands
- Content
View full analysis
Vulnerability Details
File Location:
scripts/check_lab_artifacts.py:20-25, 52-54
Vulnerability Type: Incomplete validation and insufficient dangerous-command detection
Risk Level: MediumVulnerable Code:
python DANGEROUS_PATTERNS = ( re.compile(r"\bssh\b.*\b192\.168\.123\.", re.IGNORECASE), re.compile(r"\bscp\b.*\b192\.168\.123\.", re.IGNORECASE), re.compile(r"\bdds\b.*\b(pub|publish|write|send)\b", re.IGNORECASE), re.compile(r"\bros2\s+topic\s+pub\b", re.IGNORECASE), )python prompts = "\n".join(use_case.get("prompt", "") for use_case in payload.get("use_cases", [])) if any(pattern.search(prompts) for pattern in DANGEROUS_PATTERNS): print("dangerous robot/network command pattern found in prompts", file=sys.stderr) return 1Technical Analysis
The validator searches only the
promptproperty of each object underuse_cases. It does not inspect other potentially executable or user-facing content, such as runbooks, reports, flow data, gate details, or additional JSON properties. Consequently, prohibited robot-control or robot-network commands can be placed outside the narrowly inspected fields without detection.The denylist is also incomplete relative to the safety boundaries in
SKILL.md. It recognizes only selected SSH/SCP commands targeting addresses beginning with192.168.123., selected DDS wording, andros2 topic pub. It does not generally detect alternate robot addresses, ROS service or action calls, Unitree SDK actuation APIs, command aliases, shell indirection, or multiline variants.In addition, required gate statuses are accepted as assertions supplied by the artifact rather than derived from independently validated evidence. An artifact can therefore claim that safety gates passed even when uninspected content contradicts those claims.
Attack Path
- Create a review JSON artifact containing every required gate name.
- Mar ...[truncated 1282 chars]
- Remediation
View remediation
Remediation Suggestions
- Define and enforce a strict JSON schema, including expected types for gates, use cases, reports, runbooks, flow data, and other artifact fields.
- Recursively inspect every user-facing or potentially executable text field rather than only
use_cases[*].prompt. - Reject unknown fields that could conceal executable instructions, or explicitly classify each field as safe metadata versus content requiring safety validation.
- Prefer allowlisted, structured representations of permitted operations over a regex-only denylist.
- Expand detection to cover ROS topics, services, and actions; DDS publication variants; Unitree SDK motor and sport-mode APIs; remote-access commands; alternate robot subnets; multiline commands; shell indirection; aliases; and encoded command forms.
- Derive required safety-gate results from validator evidence instead of trusting artifact-supplied
statusvalues. - Add negative tests containing dangerous commands in every supported text field and using syntax variants not covered by the current patterns.
- Keep the checker advisory unless enforcement can guarantee complete semantic analysis, and clearly document residual limitations to prevent users from treating a passing result as proof of operational safety.
