T09 · Insecure Skill Coding Practices
- Location
helper.js:151- Finding
Shell Command Injection Through Repository URL and Branch Parameters
- Content
View full analysis
{ try { return execSync(`git ${args.join(' ')}`, { encoding: 'utf8', maxBuffer: 10 * 1024 * 1024, cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] }); } catch (e) { return e.stdout || e.message; } }; const repoExists = fs.existsSync(path.join(localPath, '.git')); if (!repoExists) { execSync(`git clone "${url}" "${localPath}" --depth=100`, { encoding: 'utf8', maxBuffer: 50 * 1024 * 1024, stdio: ['ignore', 'pipe', 'pipe'] }); const commit = execSync(`git rev-parse HEAD`, { encoding: 'utf8', cwd: localPath }).trim(); return { isInitial: true, repo: repo.name, commit }; } try { execSync(`git fetch origin`, { cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] }); execSync(`git reset --hard origin/${branch}`, { cwd: localPath, stdio: ['ignore', 'pipe', 'pipe'] }); } catch (e) { try { execSync(`gi ...[truncated 3136 chars]- Remediation
View remediation
