T09 · Insecure Skill Coding Practices
- Location
scripts/text-scan.py:77- Finding
Unbounded Input Loading Can Cause Memory Exhaustion
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a local text-search helper with no network, credential, persistence, or hidden execution behavior, though it overstates its large-file efficiency.
Install only if you want a simple local text search utility. Be aware that it is not truly streaming: scanning very large files or unbounded stdin may consume substantial memory, and --output can overwrite the specified file.
scripts/text-scan.py:77Unbounded Input Loading Can Cause Memory Exhaustion
The documentation says 'If no --query is given, reads from stdin for the query,' implying query text can come from stdin. However, argparse marks --query as required at L111, and the stdin-handling branch at L125-L160 reads stdin as the text corpus to scan, not as the query. This is an active contradiction between documented intent and actual behavior.
The example 'cat LOG.md | python3 text-scan.py --query "weather" --fuzzy' suggests stdin is used as the content source, which does match implementation, but it conflicts with the preceding documentation at L16 about stdin supplying the query. Taken together, the inline documentation presents contradictory intent about what stdin is for. The code consistently uses stdin for file content only.
The script writes scan results to a user-specified file via --output, but the code path performing the write has no confirmation prompt, comment, or user-facing notice at the point of the file write. For code files, file writes should have some visible disclosure unless already clearly explained; here the operation is only implied by the CLI flag and executed silently.
No suspicious patterns detected.