T01 · Skill Instruction Hijacking
- Location
github_reader_v3_secure.py:305- Finding
Untrusted GitHub README Content Is Embedded in Agent-Consumable Output
- Content
View full analysis
Optional[str]: """获取 README 内容(截取前 3000 字符用于摘要)""" if not validate_repo_name(owner) or not validate_repo_name(repo): return None async with self.semaphore: data = await self._api_get( safe_url_join('https://api.github.com/repos', owner, repo, 'readme') ) if not data: return None content = data.get('content', '') if not content: return None try: import base64 decoded = base64.b64decode(content).decode('utf-8', errors='replace') return decoded[:3000] except Exception: return None ``` ```python # 从 README 提取摘要 summary_lines = [] if readme_raw: for line in readme_raw.split('\n'): clean = line.strip() if clean and not clean.startswith('#') and not clean.startswith('![') \ and not clean.startswith('<') and len(clean) > 20: summary_lines.append(clean[:200]) if len(summary_lines) >= 5: break report['readme_snippets'] = summary_lines ``` ```python def _render_markdown(self, report: Dict) -> str: owner = report['owner'] repo = report['repo'] info = report.get('github_info', {}) snippets = report.get('readme_snippets', []) github_url = report['github_url'] description = info.get('description', '这是一个开源项目。') snippet_block = '\n'.join(f'> {s}' for s in snippets) if snippets else '> *(README 暂无摘要)*' archived_note = '\n> ⚠️ **注意**:此仓库已被归档(只读)\n' if info.get('archived') else '' return f"""# 📦 {owner}/{repo} 深度解读报告 > **分析时间**: {datetime.now().strftime('%Y-%m-%d %H:%M')} > **数据来源**: GitHub REST ...[truncated 2819 chars]- Remediation
View remediation
