T09 · Insecure Skill Coding Practices
- Location
handler.ts:91- Finding
Unbounded Log Input Can Cause Resource Exhaustion
- Content
View full analysis
- Remediation
View remediation
MAX_LOGS) { errors.push(`"logs" must contain no more than ${MAX_LOGS} entries`); } ``` 2. Validate every log entry before processing: - Require `timestamp` to be a bounded string in an accepted timestamp format. - Require `level` to be one of `error`, `warn`, `info`, or `debug`. - Require `message` to be a string. - If present, require `context` and `stack` to be strings. 3. Apply explicit length limits, for example: - `timestamp`: 64 characters - `message`: 4–16 KB, based on operational requirements - `context`: 1 KB - `stack`: 32–64 KB 4. Reject requests whose aggregate serialized or calculated input size exceeds a configured maximum. 5. Avoid repeatedly scanning very large arrays where possible. Compute error, warning, and slow-operation counters during a single bounded pass. 6. Configure runtime-level request body, execution-time, and memory limits as defense in depth. 7. Add automated tests covering: - Exactly 10,000 entries - More than 10,000 entries - Oversized fields - Missing and non-string `message` values - Invalid log levels and timestamps ]]>
