T09 · Insecure Skill Coding Practices
- Location
scripts/harness.py:58- Finding
Evidence Verification Is Not Bound to the Claimed Source Document
- Content
View full analysis
= 0: preview = content[max(0, idx - 10):idx + len(evidence) + 30] return {"verified": True, "found_in": txt_file, "match_preview": preview.replace('\n', ' ')[:80]} # 降级:模糊匹配前30字符 idx = content.find(query) ``` ```python # scripts/batch_extract.py:99-102 txt_name = Path(f).stem + '.txt' txt_path = os.path.join(args.output, txt_name) with open(txt_path, 'w', encoding='utf-8') as wf: wf.write(r.get('text', '')) ``` ### Technical Analysis `verify_evidence()` retrieves the issue's claimed source filename into `filename`, but never uses that variable when selecting the text to search. Instead, it searches every `.txt` file in the extraction directory and accepts the first exact match or a match of only the first 30 characters. Consequently, evidence from one document can validate a finding attributed to an entirely diffe ...[truncated 1793 chars]- Remediation
View remediation
