T09 · Insecure Skill Coding Practices
- Location
scripts/obsidian_core_notes.py:365- Finding
Unredacted Sensitive File Content Is Copied into Generated Markdown Notes
- Content
View full analysis
tuple[list[str], list[str], str, str]: data, truncated = read_limited_bytes(path, limit) text, encoding, error = decode_text(data) lines = text.splitlines() nonempty = [line.strip()[:180] for line in lines if line.strip()][:8] summary = [f"{label} sample: {len(lines)} lines, {len(text)} chars."] if nonempty: summary.append("Opening: " + nonempty[0]) key_terms = keywords(text) if key_terms: summary.append("Keywords: " + ", ".join(key_terms)) notes = [f"encoding={encoding}"] if truncated: notes.append("sampled beginning only") if error: notes.append("decode fallback used") return summary, notes, text[:MAX_PREVIEW_CHARS], "text" ``` ```python def summarize_json(path: Path) -> tuple[list[str], list[str], str, str]: data, truncated = read_limited_bytes(path, MAX_JSON_BYTES) text, encoding, error = decode_text(data) notes = [f"encoding={encoding}"] summary: list[str] = [] preview = text[:MAX_PREVIEW_CHARS] try: parsed = json.loads(text) if isinstance(parsed, dict): keys = list(parsed.keys()) summary.append(f"JSON object with {len(keys)} top-level keys.") if keys: summary.append("Top keys: " + ", ".join(map(str, keys[:15]))) elif isinstance(parsed, list): summary.append(f"JSON array with {len(parsed)} items.") else: summary.append(f"JSON scalar: {type(parsed).__name__}") preview = json.dumps(parsed, ensure_ascii=False, indent=2)[:MAX_PREVIEW_CHARS] except Exception as error_json: summary.append(f"JSON parse ...[truncated 3340 chars]- Remediation
View remediation
