T09 · Insecure Skill Coding Practices
- Location
stock_analysis_v5.py:343- Finding
Caller-Controlled SQL Identifier Enables Destructive Database Operations
- Content
View full analysis
``` A caller that can invoke `save_to_db` and control `table_name` can select another valid table in the same SQLite database for deletion. Python's SQLite driver generally rejects multiple statements passed to a single `execute` call, which limits common stacked-query payloads, but does not prevent abuse of the intended `DROP TABLE` operation with an attacker-selected table name. The hard-coded database path under `/root/.openclaw/workspace-financemaster/` also creates a cross-workspace integrity concern. If the process has access to that path and the database is shared with other functionality, the operation may affect state beyond this package. ### Attack Path 1. An integration, wrapper, or other local calle ...[truncated 1235 chars]- Remediation
View remediation
