Summary
The CLI registers a --yes boolean flag that sets SkipConfirmation, and ConfirmPurchase returns true immediately when it is set, ahead of both the TTY check and the prompt. A single discoverable flag removes the only remaining human gate on a non-reversible, multi-thousand-dollar reserved-instance purchase. The project's standing rule is that the confirmation runs on every invocation. There is a TestDryRunFlagRemoved guard against reintroducing --dry-run, but nothing equivalent guards --yes.
Location
cmd/main.go:124 at 3c0f8ac
cmd/helpers.go:207-215 (the early return in ConfirmPurchase)
Failure scenario
An operator runs cudly --purchase --yes. ConfirmPurchase(..., skipConfirmation=true) returns true without printing the "About to purchase N instances" line and without reading stdin. The purchase proceeds unattended. The flag reaches exactly two call sites, the main purchase path at cmd/multi_service.go:158 and the CSV per-region prompt at cmd/multi_service.go:701. Dry runs are unaffected, since both sites sit behind a !isDryRun guard and dry runs never prompt.
Evidence
rootCmd.Flags().BoolVar(&toolCfg.SkipConfirmation, "yes", false, "Skip confirmation prompt for purchases (use with caution)")
Suggested fix
Remove the flag and the SkipConfirmation field, drop the parameter from ConfirmPurchase, and add a regression test asserting rootCmd.Flags().Lookup("yes") == nil alongside the existing TestDryRunFlagRemoved in cmd/effective_dry_run_test.go.
Found by the 2026-09-02 codebase audit, finding A10-005, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.
Summary
The CLI registers a
--yesboolean flag that setsSkipConfirmation, andConfirmPurchasereturnstrueimmediately when it is set, ahead of both the TTY check and the prompt. A single discoverable flag removes the only remaining human gate on a non-reversible, multi-thousand-dollar reserved-instance purchase. The project's standing rule is that the confirmation runs on every invocation. There is aTestDryRunFlagRemovedguard against reintroducing--dry-run, but nothing equivalent guards--yes.Location
cmd/main.go:124at 3c0f8accmd/helpers.go:207-215(the early return inConfirmPurchase)Failure scenario
An operator runs
cudly --purchase --yes.ConfirmPurchase(..., skipConfirmation=true)returns true without printing the "About to purchase N instances" line and without reading stdin. The purchase proceeds unattended. The flag reaches exactly two call sites, the main purchase path atcmd/multi_service.go:158and the CSV per-region prompt atcmd/multi_service.go:701. Dry runs are unaffected, since both sites sit behind a!isDryRunguard and dry runs never prompt.Evidence
Suggested fix
Remove the flag and the
SkipConfirmationfield, drop the parameter fromConfirmPurchase, and add a regression test assertingrootCmd.Flags().Lookup("yes") == nilalongside the existingTestDryRunFlagRemovedincmd/effective_dry_run_test.go.Found by the 2026-09-02 codebase audit, finding
A10-005, reported by one reviewer and independently confirmed by a second. Full report:docs/audits/codebase-audit-2026-09-02.md.