Back to skill

Security audit

Easycode Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Java code generator, but it handles database secrets and local command execution in ways users should review before installing.

Review this skill carefully before installing. Avoid entering real database passwords unless the state persistence is fixed, remove the hardcoded database defaults, use table_columns instead of live JDBC when possible, only allow trusted JDBC driver jars, and do not enable project formatting unless the exact command is reviewed and trusted.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/easycode_skill.py:1044
Finding

Plaintext Database Password Persisted and Exposed Through State Output

Content
View full analysis

Vulnerability Details

File Location: scripts/easycode_skill.py:1044-1050, scripts/easycode_skill.py:1055-1069, and scripts/easycode_skill.py:1151-1153
Vulnerability Type: Plaintext credential storage and disclosure
Risk Level: High

Vulnerable Code

python
return {
    "db_connection": {
        "db_type": db_type,
        "url": url,
        "user": user,
        "pass": passw,
        "driver_jar": driver_jar,
        "driver_class": driver_class,
    },
    "generation_config": gen,
}
python
def cmd_state(args: argparse.Namespace) -> int:
    state = _load_state()
    if args.show:
        print(json.dumps(state, ensure_ascii=False, indent=2))
        return 0

    if args.save:
        if not args.spec:
            raise SystemExit("--save requires --spec")

        spec = _parse_spec(args.spec)
        merged = merge_with_state(spec, state)

        merged["updated_at"] = _now_iso()
        _save_state(merged)
        print(str(STATE_FILE))
        return 0
python
merged["updated_at"] = _now_iso()
_save_state(merged)

The underlying state writer stores the supplied object without removing sensitive fields:

python
def _save_state(state: dict) -> None:
    STATE_DIR.mkdir(parents=True, exist_ok=True)
    with STATE_FILE.open("w", encoding="utf-8") as f:
        json.dump(state, f, ensure_ascii=False, indent=2)

Technical Analysis

Interactive configuration places the database password in db_connection.pass. Both the explicit state --save operation and a successful interactive run pass the complete merged configuration to _save_state. No redaction, encryption, secret-manager integration, or restrictive file mode is applied.

The resulting .easycode-skill/state.json therefore contains the password in plaintext. The state --show command subsequently prints the entire state object, including that passw ...[truncated 1609 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove pass before every call to _save_state:
    python
    persisted = copy.deepcopy(merged)
    persisted.get("db_connection", {}).pop("pass", None)
    _save_state(persisted)
    
  2. Request the password for each metadata-fetch operation or accept it through a protected secret input channel.
  3. If reuse is required, persist only a secret-manager reference and resolve it at runtime.
  4. Redact sensitive fields in state --show, including passwords and any future tokens.
  5. Create the state directory with restrictive permissions and write the state file with mode 0600.
  6. Add automated tests confirming that serialized state and command output never contain pass.
  7. Document .easycode-skill/ in recommended ignore rules to reduce accidental commits.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/easycode_skill.py:439
Finding

Database Password Exposed in Child-Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/easycode_skill.py:439-452 and scripts/java/JdbcMetadataBridge.java:9-15
Vulnerability Type: Sensitive information exposure through process arguments
Risk Level: Medium

Vulnerable Code

python
args = [
    "--db-type", db_type,
    "--url", dbc["url"],
    "--user", dbc["user"],
    "--pass", dbc["pass"],
    "--tables", ",".join(table_names),
    "--number-type", number_type,
    "--time-type", time_type,
]
if driver_class:
    args.extend(["--driver-class", driver_class])

try:
    out_raw = _run_java_main(JAVA_METADATA_MAIN_CLASS, args, extra_jars=extra_jars)

The Java bridge receives the secret directly from its argument array:

java
Map<String, String> a = parseArgs(args);
String dbType = req(a, "db-type");
String url = req(a, "url");
String user = req(a, "user");
String pass = req(a, "pass");
String tablesRaw = req(a, "tables");

Technical Analysis

The Skill starts the Java metadata bridge with the database password embedded in its command line. On systems where process arguments are visible to other users, administrators, monitoring agents, diagnostic tools, or container observers, the password can be captured while the process is running.

Although subprocess.run uses an argument list and does not invoke a shell, that only mitigates shell injection. It does not protect sensitive values placed in the process argument vector. Supplying database credentials to JDBC is necessary, but exposing them through command-line arguments is not.

Attack Path

  1. A user requests a generation plan or execution without supplying table_columns.
  2. The Skill automatically starts JDBC metadata retrieval.
  3. Python places dbc["pass"] after the --pass option in the Java process argument vector.
  4. A local observer queries process metadata or captures it through monitoring, audit, diagnostic, or crash-r ...[truncated 568 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not place passwords in command-line arguments.
  2. Pass the credential through standard input, an inherited file descriptor, or a temporary file created with mode 0600.
  3. If a temporary credential file is used, delete it in a finally block and ensure it is never included in logs or exception messages.
  4. Prefer an in-process JDBC integration or a secret-provider interface where feasible.
  5. Ensure Java and Python error handling redacts passwords, JDBC URLs containing credentials, and other secret fields.
  6. Add tests that inspect the child-process command and verify that no secret value appears in its argument vector.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/easycode_skill.py:737
Finding

Caller-Controlled Formatter Command Enables Arbitrary Local Program Execution

Content
View full analysis

Vulnerability Details

File Location: scripts/easycode_skill.py:737-765
Vulnerability Type: Unsafe execution of configuration-controlled commands
Risk Level: High

Vulnerable Code

python
def _run_project_formatter(gen: Dict[str, Any]) -> Dict[str, Any]:
    project_root = Path(gen.get("project_root", ".")).resolve()
    custom = gen.get("project_format_command")
    commands: List[List[str]] = []

    if isinstance(custom, str) and custom.strip():
        commands.append(shlex.split(custom))
    elif isinstance(custom, list) and custom:
        for c in custom:
            if isinstance(c, str) and c.strip():
                commands.append(shlex.split(c))
    else:
        commands = _candidate_project_format_commands(project_root)

    if not commands:
        return {
            "formatter_run": False,
            "formatter_success": False,
            "formatter_command": "",
            "formatter_message": "No formatter command configured or detected.",
        }

    for cmd in commands:
        try:
            proc = subprocess.run(
                cmd,
                cwd=str(project_root),
                capture_output=True,
                text=True,
            )
        except Exception as exc:
            continue

Technical Analysis

generation_config.project_format_command can specify an arbitrary executable and arbitrary arguments. When --run-project-format is enabled, the value is parsed with shlex.split and passed directly to subprocess.run.

The implementation correctly avoids shell=True, so shell metacharacters are not interpreted automatically. Nevertheless, the first argument can identify any executable accessible to the Agent account, and arguments may request destructive or data-exfiltrating behavior. There is no executable allowlist, path confinement, argument validation, integrity check, or mandatory confirmation of ...[truncated 1388 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove support for arbitrary formatter commands from externally supplied specifications.
  2. Maintain an allowlist of supported formatters and fixed task names, such as trusted project-local gradlew or mvnw wrappers with predefined arguments.
  3. Resolve executable paths and ensure they remain within the explicitly selected project root or a trusted system-tool directory.
  4. Reject path traversal, unexpected executable names, interpreter commands, and unapproved arguments.
  5. Display the exact resolved executable and arguments and require explicit user confirmation before execution.
  6. Run formatting in a sandbox with restricted filesystem and network access where available.
  7. Do not persist executable command strings in reusable state.

T08 · Insecure Dependencies

Error
Location
scripts/easycode_skill.py:416
Finding

Caller-Selected JDBC JAR and Class Allow Arbitrary Code Execution During Driver Loading

Content
View full analysis

Vulnerability Details

File Location: scripts/easycode_skill.py:416-423, scripts/easycode_skill.py:439-452, and scripts/java/JdbcMetadataBridge.java:15-22
Vulnerability Type: Untrusted dependency loading
Risk Level: High

Vulnerable Code

python
driver_jar = dbc.get("driver_jar", "").strip()
driver_class = dbc.get("driver_class", "").strip()

extra_jars: List[str] = []
if driver_jar:
    if not Path(driver_jar).exists():
        return {}, {}, f"driver_jar not found: {driver_jar}"
    extra_jars.append(driver_jar)
python
if driver_class:
    args.extend(["--driver-class", driver_class])

try:
    out_raw = _run_java_main(JAVA_METADATA_MAIN_CLASS, args, extra_jars=extra_jars)
java
String driverClass = a.getOrDefault("driver-class", defaultDriverClass(dbType));
String numberType = a.getOrDefault("number-type", "Long");
String timeType = a.getOrDefault("time-type", "Date");

if (driverClass != null && !driverClass.isBlank()) {
    Class.forName(driverClass);
}

Technical Analysis

Both db_connection.driver_jar and db_connection.driver_class are caller-controlled. The Python layer verifies only that the JAR path exists before adding it to the Java classpath. The Java bridge then invokes Class.forName using the supplied class name.

Loading a Java class initializes it by default. A malicious class can therefore execute arbitrary logic from a static initializer before any JDBC metadata operation occurs. The JAR does not need to implement a functional JDBC driver to trigger this behavior.

Loading a JDBC driver is legitimate for database metadata retrieval, but accepting arbitrary local JARs and class names without origin or integrity validation exceeds minimum dependency privileges.

Attack Path

  1. An attacker creates or places a malicious JAR on a path readable by the Agent.
  2. The JAR contains a class with a malicious static initi ...[truncated 1013 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not accept arbitrary JDBC driver class names. Map each validated db_type to a fixed expected driver class.
  2. Restrict JAR lookup to trusted, administrator-configured directories.
  3. Canonicalize paths and reject files outside those directories, including symbolic-link escapes.
  4. Pin approved driver versions and verify cryptographic hashes or signatures before loading.
  5. Avoid selecting arbitrary wildcard matches from user-controlled locations.
  6. Run the metadata bridge in a sandbox with minimal filesystem access, no unnecessary environment secrets, and constrained network access.
  7. Require explicit confirmation when a non-bundled driver is selected and display its canonical path and verified digest.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/easycode_skill.py:399
Finding

Hardcoded Database Password and Internal Oracle Endpoint in Generated Specification Defaults

Content
View full analysis

Vulnerability Details

File Location: scripts/easycode_skill.py:399-405 and scripts/easycode_skill.py:499-509
Vulnerability Type: Hardcoded credentials and infrastructure information exposure
Risk Level: High

Vulnerable Code

python
def _default_jdbc_url(db_type: str) -> str:
    m = {
        "mysql": "jdbc:mysql://localhost:3306/demo?useUnicode=true&characterEncoding=UTF-8&serverTimezone=Asia/Shanghai",
        "postgresql": "jdbc:postgresql://localhost:5432/demo",
        "oracle": "jdbc:oracle:thin:@//10.96.1.32:1521/wghisfat",
        "sqlserver": "jdbc:sqlserver://localhost:1433;databaseName=demo;encrypt=false",
    }
    return m.get(db_type, "")
python
out = {
    "db_connection": {
        "db_type": db_type,
        "url": args.url or _default_jdbc_url(db_type),
        "user": args.user or "emr",
        "pass": args.password or "Wgfat_2022",
        "driver_class": first_driver[0] or _default_driver_class(db_type),
        "driver_jar": first_driver[1] or "",
    },

Technical Analysis

The spec-template command emits a fixed username and password whenever the caller does not supply alternatives. The Oracle default also identifies a private IP address, port, and service name. These values appear environment-specific rather than neutral placeholders.

The audit cannot establish whether the credentials remain valid. Nevertheless, embedding and distributing real-looking credentials is an insecure practice. If valid or reused, anyone with access to the Skill package can recover them. Even if invalid, generated configurations may encourage unsafe credential handling and can subsequently be persisted by the state mechanism.

Default database connectivity is not required for generating a specification template. Placeholders or mandatory user input provide the declared functionality without exposing credentials or infrastructure details.

Attac

...[truncated 1107 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the hardcoded username, password, private IP address, and service name from source control.
  2. Replace defaults with unmistakable placeholders such as DB_HOST, DB_USER, and a password value that must be supplied securely.
  3. Do not emit a password in spec-template; require runtime secret input instead.
  4. Rotate the exposed password immediately if it is valid or has been reused in any environment.
  5. Review repository history, logs, and distributed package versions for prior exposure.
  6. Use neutral localhost examples without organization-specific service names.
  7. Add secret-scanning checks to CI to prevent future hardcoded credential commits.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (32)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The memory policy is internally contradictory: it says plaintext passwords must not be stored, but also states interactive mode persists pass for next-run defaults. This creates a clear risk of credential retention in local state, exposing database passwords to other users, processes, logs, backups, or accidental commits.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This functionality explicitly supports execution of arbitrary formatting commands unrelated to the core task of template-based code generation. In the context of an agent skill, this materially expands capability from file generation into command execution on the host, enabling abuse such as running attacker-chosen binaries or project-provided wrappers.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/easycode_skill.py (reported line 1182)May include surrounding context.

python
execute = sub.add_parser("execute", help="write rendered files")
    execute.add_argument("--spec", type=str, required=True, help="JSON payload")
    execute.add_argument("--overwrite", action="store_true", help="overwrite existing files")
    execute.add_argument("--run-project-format", action="store_true", help="run project formatter after file generation")
    execute.add_argument("--interactive-type-mapping", action="store_true", help="prompt for type mapping when not specified")
    execute.set_defaults(func=cmd_execute)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/easycode_skill.py (reported line 1204)May include surrounding context.

python
execute = sub.add_parser("execute", help="write rendered files")
    execute.add_argument("--spec", type=str, required=True, help="JSON payload")
    execute.add_argument("--overwrite", action="store_true", help="overwrite existing files")
    execute.add_argument("--run-project-format", action="store_true", help="run project formatter after file generation")
    execute.add_argument("--interactive-type-mapping", action="store_true", help="prompt for type mapping when not specified")
    execute.set_defaults(func=cmd_execute)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents use of shell, file read/write, and environment-like capabilities but does not declare a restrictive tool scope or permission boundary. In an agent setting, this increases the chance the skill can invoke commands or modify files beyond intended code-generation tasks, especially because it reads local state and executes scripts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow allows running a project formatter command and the renderer status further permits custom project_format_command values. That extends the skill from deterministic code generation into arbitrary command execution, creating command-injection and abuse risk if untrusted input can influence the formatter command.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's activation and default prompt are broad enough that the agent may invoke this capability for loosely related requests involving databases, Java generation, or prior configuration reuse. Because the skill also references memory of last-used config, over-broad triggering can cause unintended use of stored settings or code-generation actions in contexts where the user did not clearly request them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated PO template includes @JsonFormat(locale = "zh", timezone = "GMT+8", ...), which forces a specific language/locale and timezone choice in all generated code. This is a natural-language policy issue because the file embeds a fixed locale preference rather than offering configurability or documenting a region-specific requirement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for generating Java code from database tables using EasyCode-style templates and producing a generation plan/execution, which fits code generation mechanics. However, this configuration specifically scaffolds runtime business capabilities including add, edit, delete, REST endpoints, repository services, and application services, turning the skill into a full-stack CRUD scaffolder rather than a narrowly described generator utility.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill for generating Java code from database tables with EasyCode-style templates and planning/executing file generation. This configuration goes further by defining end-to-end persistence, service, application, DTO/VO, assembler, REST facade, and delete/update/add operations, effectively scaffolding a full CRUD backend rather than narrowly table-to-code generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template hard-codes @JsonFormat(locale = "zh", timezone = "GMT+8", ...) into generated classes. This imposes a specific language/locale behavior on all generated code without offering a choice or documenting that the skill is region-specific, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The repository template's pageList and findAllByParams methods accept filter objects but construct an empty LambdaQueryWrapper and return all rows, despite claiming parameter-based filtering. In this skill context, that can silently generate data-access code that overexposes records, weakens tenant/data minimization assumptions, and may cause unauthorized bulk data retrieval when downstream developers trust the generated method names and comments.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The state-saving logic persists the merged db_connection object, including the database password, to a local JSON state file without any indication in the skill description. Undisclosed credential persistence is dangerous because it leaves reusable secrets on disk where other local users, backups, or tooling may access them.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/easycode_skill.py (reported line 302)May include surrounding context.

python
"-d",
            str(JAVA_BUILD_DIR),
        ] + java_sources
        proc = subprocess.run(cmd, capture_output=True, text=True)
        if proc.returncode != 0:
            raise SystemExit(f"Failed to compile Java bridge:\n{proc.stderr}")
        marker.write_text(_now_iso(), encoding="utf-8")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/easycode_skill.py (reported line 313)May include surrounding context.

python
"-d",
            str(JAVA_BUILD_DIR),
        ] + java_sources
        proc = subprocess.run(cmd, capture_output=True, text=True)
        if proc.returncode != 0:
            raise SystemExit(f"Failed to compile Java bridge:\n{proc.stderr}")
        marker.write_text(_now_iso(), encoding="utf-8")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill connects to live databases and retrieves schema metadata via JDBC, but this behavior is not transparently disclosed in the described skill purpose. That matters because users may assume offline template generation, while the skill actually initiates network/database access and processes sensitive metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The spec template emits a real-looking default password value unrelated to safe templating behavior. This can normalize insecure secret handling, lead users to accidentally reuse or expose a sensitive credential, and suggests the value may have been copied from a real environment.

Content

No source excerpt is available for this finding.

Tainted flow: 'target' from os.environ.get (line 653, credential/environment) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/easycode_skill.py (reported line 710)May include surrounding context.

python
continue

        target.parent.mkdir(parents=True, exist_ok=True)
        target.write_text(content, encoding="utf-8")
        written.append(item["path"])

    return {

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Auto-detecting and executing local gradlew or mvnw scripts is effectively executing code from the target repository, since those wrapper scripts are project-controlled. In a code-generation skill, this increases danger because a malicious or compromised repository can turn a 'format' step into arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

The skill can execute user-supplied project_format_command values via subprocess, and even when custom commands are absent it auto-runs local wrapper scripts like gradlew or mvnw from the target project. In a skill context, this is dangerous because generating code should not require executing arbitrary project commands, and build wrappers are code execution entry points controlled by the project being operated on.

Content

Scanner excerpt · scripts/easycode_skill.py (reported line 762)May include surrounding context.

python
for cmd in commands:
        try:
            proc = subprocess.run(
                cmd,
                cwd=str(project_root),
                capture_output=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Database credentials are passed as command-line arguments to a Java subprocess, which may expose them to local process inspection tools, shell history analogs in wrappers, or diagnostic logs. Users are not warned that secrets leave the Python process boundary in this way.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

Interactive execution saves merged state, which includes database connection details and password, to .easycode-skill/state.json after generation without a dedicated warning or explicit consent. Silent credential persistence creates lasting exposure beyond the immediate session and is especially risky on shared workstations or synced home directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Execute mode writes generated files directly to disk with no interactive confirmation, which can overwrite or create files in attacker-influenced locations if the spec or templates are untrusted. In an agent skill, non-interactive file writes are a meaningful safety issue because the agent may be induced to modify a codebase unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The program accepts database credentials via command-line arguments, which commonly exposes secrets through shell history, process listings, job control tools, logging, and CI telemetry. In this skill context, the tool is meant to be invoked by automation for code generation, which increases the chance that credentials are handled non-interactively and leaked unintentionally across local or shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code reads both a template file and a context JSON file directly from user-supplied command-line paths, which is a file-access operation covered by the warning requirement for code files. The file contains no confirmation prompt, logging/print disclosure before the reads, and no explanatory comments or docstrings indicating that local files will be accessed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.