T09 · Insecure Skill Coding Practices
- Location
scripts/graph_rule_engine.py:202- Finding
Unbounded Duplicate Inference Materialization Causes Resource Exhaustion
- Content
View full analysis
None: """Add edge to graph.""" source = edge.get('source') target = edge.get('target') if source and target: if source not in self.edges: self.edges[source] = {} if target not in self.edges: self.edges[target] = {} if target not in self.edges[source]: self.edges[source][target] = [] self.edges[source][target].append(edge) ``` ### Technical Analysis The engine stores inferred fact identities in the `inferred_facts` set, which deduplicates tuples of `(source, target, relationship type)`. However, the result of the set i ...[truncated 2793 chars]- Remediation
View remediation
bool: source = edge.get("source") target = edge.get("target") rel_type = edge.get("type") if not source or not target: return False fact = (source, target, rel_type) if fact in self.inferred_facts: return False self.inferred_facts.add(fact) self.edges.setdefault(source, {}) self.edges.setdefault(target, {}) self.edges[source].setdefault(target, []).append(edge) return True ``` 2. **Count only genuinely new facts** Increment `iteration_inferences` and `total_inferences` only when `_add_edge()` returns `True`. Do not use the raw length of `result.inferences_generated` for fixpoint detection. 3. **Use iteration-local deduplication** Deduplicate generated facts within each iteration before insertion. This prevents multiple matching rules or duplicate pattern matches from emitting the same fact repeatedly. 4. **Enforce configured safety controls** Implement the declared `cycle_detection` option and enforce each rule's `max_depth`. Reject or constrain self-referential and mutually recursive rule dependencies where appropriate. 5. **Apply explicit resource budgets** Add configurable limits for: - Maximum inferred facts. - Maximum total edges. - Maximum matches per rule. - Maximum execution time. - Maximum memory-oriented work units. - Maximum iterations, using a conservative default. Execution should terminate with a clear failure result when a limit is reached. 6. **Validate untrusted input** Before execution, estimate rule expansion risk and reject malformed, self-reinforcing, or excessively broad rules supplied by untrusted users. 7. **A ...[truncated 257 chars]
