T09 · Insecure Skill Coding Practices
- Location
scripts/pr-review.sh:259- Finding
Arbitrary Python Code Execution Through Attacker-Controlled PR Filenames
- Content
View full analysis
/dev/null || echo "" } ``` ```bash check_test_coverage() { python3 -c " import sys files = '''$1'''.strip().split('\n') src, tests = [], [] for f in files: f = f.strip() if not f: continue if f.endswith('_test.go') or 'test_' in f.split('/')[-1] or f.endswith('_test.py') or f.endswith('.test.ts') or f.endswith('.test.js') or f.endswith('.spec.ts') or f.endswith('.spec.js'): tests.append(f) elif f.endswith(('.go', '.py', '.ts', '.tsx', '.js', '.jsx')): src.append(f) missing = [] for s in src: has_test = False s_dir = '/'.join(s.split('/')[:-1]) s_name = s.split('/')[-1].rsplit('.', 1)[0] for t in tests: t_dir = '/'.join(t.split('/')[:-1]) if t_dir == s_dir or f'test_{s_name}' in t or f'{s_name}_test' in t or f'{s_name}.test' in t or f'{s_name}.spec' in t: has_test = True break skip = any(k in s for k in ['__init__', 'main.go', 'main.py', 'config', 'types', 'models', 'schema', 'index.ts', 'index.js']) if not has_test and not skip: missing.append(s) if missing: print('Files without corresponding test changes:') for f in missing: print(f' - {f}') else: print('Test coverage looks adequate for changed files.') " } ``` The data flow into the vulnerable function is: ```bash files=$(get_pr_files "$pr_num") test_coverage=$(check_test_coverage "$files") ``` ### Technical Analysis GitHub pull-request contributors control the names of files included in their commits. `get_pr_files` retrieves those names and stores them i ...[truncated 2967 chars]- Remediation
View remediation
