T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_chat.py:114- Finding
Private Chat Transcripts Are Persisted and Exported in Plaintext by Default
- Content
View full analysis
CACHE_TTL: return None return entry.get("raw") def set_cached_export(chat_target, limit, raw_content): """保存导出缓存""" ensure_data_dir() key = _cache_key(chat_target, limit) try: if os.path.exists(CACHE_FILE): with open(CACHE_FILE, "r", encoding="utf-8") as f: cache = json.load(f) else: cache = {} except (json.JSONDecodeError, OSError): cache = {} cache[key] = {"ts": time_module.time(), "raw": raw_content} with open(CACHE_FILE, "w", encoding="utf-8") as f: json.dump(cache, f, ensure_ascii=False) ``` Raw transcript inclusion is enabled unconditionally by default: ```python parser.add_argument("--include-raw", action="store_true", default=True, help="输出中包含原始聊天记录(默认包含)") ``` The raw export is then copied into the generated report: ```python if args.include_raw: lines.append("\n--- 原始聊天记录 ---") lines.append(raw) lines.append("--- 原始聊天记录结束 ---") ``` ### Technical Analysis The Skill handles highly sensitive private chat records but writ ...[truncated 3228 chars]- Remediation
View remediation
