T09 · Insecure Skill Coding Practices
- Location
scripts/nova_act_runner.py:31- Finding
Material-Impact Safety Controls Are Bypassable and Prompt-Only
- Content
View full analysis
list[str]: """Check if task involves material-impact actions. Returns triggered keywords.""" task_lower = task.lower() triggered = [kw for kw in MATERIAL_IMPACT_KEYWORDS if kw in task_lower] if triggered: print(f"Safety: Material-impact keywords detected ({', '.join(triggered)}). " f"Will stop before completing irreversible actions.", file=sys.stderr) return triggered def apply_safety_guardrails(task: str, triggered_keywords: list[str]) -> str: """Append safety instructions to task prompt when material-impact keywords detected.""" if triggered_keywords: return task + SAFETY_SUFFIX return task ``` ```python triggered = check_material_impact(task) safe_task = apply_safety_guardrails(task, triggered) cookbook = load_cookbook() # Load safety guidelines at runtime api_key = os.environ.get("NOVA_ACT_API_KEY") if not api_key: print("Error: NOVA_ACT_API_KEY environment variable ...[truncated 2723 chars]- Remediation
View remediation
