T09 · Insecure Skill Coding Practices
- Location
scripts/corpus-pick.sh:21- Finding
Arbitrary Python Code Execution Through Unsafe String Interpolation
- Content
View full analysis
/dev/null || echo "$default" else echo "$default" fi } ``` ```bash FILTERED=$(python3 -c " import sys cutoff = int('$CUTOFF') history_path = '$HISTORY_PATH' # Load recently visited files recent = set() with open(history_path) as f: for line in f: parts = line.strip().split('\t', 1) if len(parts) == 2: try: ts = int(parts[0]) if ts >= cutoff: recent.add(parts[1]) except ValueError: continue # Filter candidates for line in sys.stdin: path = line.strip() if path and path not in recent: print(path) " <<< "$CANDIDATES" 2>/dev/null) || true ``` The same construction is used in `freshness-gate.sh`: ```bash DAYS=$(python3 -c "import json; c=json.load(open('$CONFIG')); print(c.get('freshness',{}).get('days',7))" 2>/dev/null || echo "7") HISTORY_FILE=$(python3 -c "import json; c=json.load(open('$CONFIG')); print(c.get('freshness',{}).get('historyFile','.random-thought-history'))" 2>/dev/null || echo ".random-thought-history") ``` ```bash FOUND=$(python3 -c " cutoff = int('$CUTOFF') target = '$ABS_FILE' with open('$HISTORY_FILE') as f: for line in f: parts = line.strip().split('\t', 1) if len(parts) == 2: ts, path = int(parts[0]), parts[1] if ts >= cutoff and path == target: p ...[truncated 2185 chars]- Remediation
View remediation
