T09 · Insecure Skill Coding Practices
- Location
change-theme.sh:133- Finding
Heuristic Global Replacement Can Corrupt Unrelated JavaScript Colors
- Content
View full analysis
=2 occurrences as the main accent) # The "danger" color (#ef4444 equivalent) should NOT be changed # Find colors that are likely the old accent (appear >= 2 times, not in standard palette) STANDARD_COLORS="007bff|00e5cc|050810|6366f1|f59e0b|dfb82b|22c55e|3b82f6|14b8a6|eab308" # Get the current accent color from CSS (we just set it, but check what was there) # We replace any color that is clearly an accent (not standard palette, appears >=2) OLD_ACCENT=$(echo "$JSCOLORS" | grep -vE "^\\s*[0-9]+\\s#($STANDARD_COLORS)$" | awk '{print $2}' | head -3) if [[ -n "$OLD_ACCENT" ]]; then echo " Replacing old accent color(s) in JS: $OLD_ACCENT" for old in $OLD_ACCENT; do # Skip if it looks like it could be the new color (idempotent check) if [[ "$old" != "$COLOR" ]]; then sed -i "s/${old}/${COLOR}/g" "$JS" echo " Replaced $old -> $COLOR" fi done else echo " No old accent color found to replace (may already be set)" fi ``` ### Technical Analysis The script infers the previous accent color by ranking every six-digit hexadecimal color in the JavaScript bundle, excluding a small hard-coded list, and selecting up to three remaining values. It then globally replaces ...[truncated 2710 chars]- Remediation
View remediation
