T09 · Insecure Skill Coding Practices
- Location
scripts/check_duplicates.py:17- Finding
Collision-Unsafe Duplicate Detection Can Delete Distinct Files
- Content
View full analysis
1 } ``` ```python for md5, files in data['duplicates'].items(): sorted_files = sorted(files, key=lambda x: x['mtime']) for file_info in sorted_files[1:]: filepath = Path(target_dir) / file_info['path'] if not dry_run: try: filepath.unlink() deleted_count += 1 freed_space += file_info['size'] except OSError as e: print(f"Warning: unable to delete {filepath}: {e}", file=sys.stderr) ``` ### Technical Analysis The duplicate detector treats matching MD5 digests as conclusive proof that files have identical contents. MD5 is collision-broken: two different byte sequences can be deliberately constructed to produce the same digest. The implementation does not perform a secondary verification based on file size, a collision-resistant digest, or byte-for-byte comparison before calling `Path.unlink()`. Consequently, distinct files with a colliding MD5 value are placed in the same duplicate group, and all but the file with the earliest modification timestamp are permanently deleted when deletion mode is approved. User confirmation reduces accidental activation but does not make the duplicate classification trustworthy. The report explicitly labels colliding files as du ...[truncated 1172 chars]- Remediation
View remediation
