T09 · Insecure Skill Coding Practices
- Location
scripts/memory_lifecycle_manager.py:64- Finding
Archive Filename Collision Can Cause Irrecoverable Memory Loss
- Content
View full analysis
Vulnerability Details
File Location:
scripts/memory_lifecycle_manager.py, lines 64–73
Vulnerability Type: Predictable archive filename collision and unsafe overwrite
Risk Level: HighVulnerable Code
python original_name = file_path.name timestamp = datetime.now().strftime("%Y%m%d") new_name = f"{original_name}_{timestamp}.md" target_path = target_dir / new_name # Copy the file into the archive directory shutil.copy2(file_path, target_path) # Remove it from the current directory file_path.unlink()Technical Analysis
Files from multiple recursively scanned modules—
current,food,training, andmisc—are flattened into a shared monthly archive directory. The generated destination filename contains only the source basename and the current date.Consequently, two source files with the same basename that are archived on the same day produce an identical
target_path. Python'sshutil.copy2()overwrites an existing destination file without requiring confirmation or raising a collision error. The script then unconditionally deletes the corresponding source withfile_path.unlink().For example, both of the following files can resolve to the same archive destination:
text memory/current/note.md memory/food/note.mdIf both are archived on the same day, they produce a destination similar to:
text memory/archived/2026-01/note.md_20260911.mdThe second copy overwrites the first archived file, and both original source files are deleted. This violates the documented guarantee that archived memories are never lost.
The naming operation also appends another
.mdsuffix to the complete original filename, resulting in names such asnote.md_20260911.md. Although this is primarily a correctness issue, it demonstrates that the original suffix is not handled safely.Attack Path
- An attacker or local user with permission to create memory files pl ...[truncated 1374 chars]
- Remediation
View remediation
Remediation Suggestions
-
Preserve each source file's module and relative directory structure inside the archive rather than flattening every module into one monthly directory. For example:
text memory/archived/2026-01/current/note.md memory/archived/2026-01/food/note.md -
Generate collision-resistant destination names when retaining a flat archive layout. Include a module identifier, high-resolution timestamp, UUID, or cryptographic content digest.
-
Check whether the destination already exists before copying. Never permit silent overwrites. On collision, generate a new unique destination or stop with an explicit error.
-
Copy to a temporary file in the destination directory, flush and synchronize it, verify its size or cryptographic digest against the source, and then atomically rename it to the final destination.
-
Delete the source only after confirming that the destination was created successfully and contains the expected data.
-
Construct filenames using
Path.stemandPath.suffixto avoid duplicated extensions, for example:python new_name = f"{file_path.stem}_{timestamp}{file_path.suffix}" -
Add automated tests covering identical basenames across different modules, repeated archival runs on the same date, pre-existing destination files, copy failures, and verification failures.
-
