T09 · Insecure Skill Coding Practices
- Location
scripts/goal_setter.sh:29- Finding
Arbitrary Python Code Execution Through Unsanitized Shell Argument Interpolation
- Content
View full analysis
[deadline]"; exit 1; } python3 << PYEOF import json, time with open("$DB") as f: goals = json.load(f) gid = max([g.get("id",0) for g in goals]+[0]) + 1 goals.append({"id":gid,"goal":"$goal","deadline":"$deadline","progress":0, "milestones":[],"status":"active","created":time.strftime("%Y-%m-%d"), "notes":""}) with open("$DB","w") as f: json.dump(goals, f, indent=2, ensure_ascii=False) print("🎯 Goal #{} set: $goal".format(gid)) if "$deadline": print(" Deadline: $deadline") PYEOF ;; milestone) goal="${1:-}"; step="${2:-}" [ -z "$goal" ] || [ -z "$step" ] && { echo "Usage: milestone "; exit 1; } python3 -c " import json with open('$DB') as f: goals = json.load(f) for g in goals: if g['goal'] == '$goal' or str(g.get('id','')) == '$goal': g.setdefault('milestones',[]).append({'step':'$step','done':False}) print('📍 Milestone added to {}: $step'.format(g['goal'])) break with open('$DB','w') as f: json.dump(goals, f, indent=2, ensure_ascii=False) ";; progress) goal="${1:-}"; pct="${2:-0}" [ -z "$goal" ] && { echo "Usage: progress "; exit 1; } python3 -c " import json with open('$DB') as f: goals = json.load(f) for g in goals: if g['goal'] == '$goal' or str(g.get('id','')) == '$goal': g['progress'] = int('$pct') bar = '█' * (int('$pct')//10) + '░' * (10-int('$pct')//10) print('📊 {} [{}] {}%'.format(g['goal'], bar, '$pct')) if int('$pct') >= 100: ...[truncated 4289 chars]- Remediation
View remediation
