T09 · Insecure Skill Coding Practices
- Location
handler.ts:95- Finding
Unenforced Log-Volume Limit Enables Resource Exhaustion
- Content
View full analysis
- Remediation
View remediation
MAX_LOGS_PER_REQUEST ) { errors.push(`"logs" must contain at most ${MAX_LOGS_PER_REQUEST} entries`); } ``` 2. Define the limit once and reuse the same constant in both validation and `handleStatus` to prevent documentation and implementation from diverging. 3. Validate every log entry, including the types and maximum lengths of `timestamp`, `level`, `message`, `context`, and `stack`. 4. Apply an overall serialized request-size limit at the API or agent boundary. 5. Consider processing large permitted inputs in bounded batches or through streaming logic rather than constructing multiple full-size intermediate arrays. 6. Configure runtime memory, execution-time, and concurrency limits as defense-in-depth controls. 7. Add tests confirming that arrays of 10,001 or more entries are rejected before analysis begins. ]]>
