T09 · Insecure Skill Coding Practices
- Location
scripts/install.sh:126- Finding
Log-Controlled Arbitrary File Disclosure and Modification
- Content
View full analysis
/dev/null; then log "Content already processed: $path" continue fi # Process the content "$(dirname "${BASH_SOURCE[0]}")/push-content.sh" "$path" "$title" content_found=$((content_found + 1)) fi fi done < "$log_file" ``` ```bash # Check if file exists if [ ! -f "$CONTENT_PATH" ]; then log "❌ Content file not found: $CONTENT_PATH" return 1 fi # Read content content=$(head -1000 "$CONTENT_PATH" 2>/dev/null || echo "Content read failed") # Create Feishu document log "Creating Feishu document: $TITLE" # Try different methods to create Feishu content if command -v openclaw >/dev/null 2>&1; then # Method 1: Send as message (fallback if document creation fails) message="📄 **Auto-Push System Notification**\n\n**Title**: $TITLE\n**Time**: $(date '+%Y-%m-%d %H:%M:%S')\n**Status**: Content generated successfully\n\n**Preview**:\n$content" openclaw message send \ --channel feishu \ --target "$TARGET_CHAT_ID" \ ...[truncated 3187 chars]- Remediation
View remediation
