T09 · Insecure Skill Coding Practices
- Location
scripts/memdb.py:291- Finding
Arbitrary Markdown File Overwrite Through an Unsanitized Memory Type
- Content
View full analysis
int: """添加记忆,自动去重(相似度>0.95则更新)""" vec = embed(content) rows = self.conn.execute("SELECT id, embedding FROM memories_vec").fetchall() for row_id, emb_bytes in rows: if emb_bytes and cosine_sim(vec, emb_bytes) > 0.95: self.conn.execute(""" UPDATE memories SET content=?, updated_at=CURRENT_TIMESTAMP, type=COALESCE(?,type), entity=COALESCE(?,entity), severity=COALESCE(?,severity) WHERE id=? """, (content, type, entity, severity, row_id)) self.conn.execute("UPDATE memories_vec SET embedding=? WHERE id=?", (vec, row_id)) self.conn.commit() return row_id ``` ```python def export_markdown(self, output_dir: str): os.makedirs(output_dir, exist_ok=True) rows = self.conn.execute( "SELECT content, type, entity, status, severity, source, created_at, updated_at FROM memories ORDER BY type, updated_at DESC" ).fetchall() by_type = {} for r in rows: t = r[1] or "note" by_type.setdefault(t, []).append(r) for t, items in by_type.items(): path = os.path.join(output_dir, f"{t}.md") with open(path, "w", encoding="utf-8") as f: f.write(f"# {t}\n\n") for item in items: content, _, entity, status, severity, source, created, updated = item date = (created or "")[:10] f.write(f"- [{date}] [{status or 'active'}] {content}") ``` ### Technical Analysis The memory `type` fie ...[truncated 2072 chars]- Remediation
View remediation
