T09 · Insecure Skill Coding Practices
- Location
scripts/generate.py:348- Finding
Default generation workflow unconditionally overwrites existing documentation
- Content
View full analysis
/README.md`, regardless of whether the file already exists. `generate_readme()` opens the selected path using mode `w`. In Python, this mode immediately truncates an existing regular file before writing the generated content. There is no existence check, backup, preview, interactive confirmation, exclusive-create mode, or explicit overwrite option. This behavior exceeds the minimum write privileges needed to generate missing documentation. The declared functionality can be implemented by creating absent documents while preserving existing files by ...[truncated 2417 chars]- Remediation
View remediation
