T09 · Insecure Skill Coding Practices
- Location
scripts/github-to-xhs.py:399- Finding
Path Traversal Through an Unsanitized Repository Slug
- Content
View full analysis
= 2: return path_parts[0], path_parts[1] return None, None def create_slug(repo_name): """Create a URL-friendly slug.""" return repo_name.lower().replace('_', '-').replace(' ', '-') def create_directory_structure(base_path, slug): """Create the output directory structure.""" dirs = [ f"{base_path}/{slug}", f"{base_path}/{slug}/prompts" ] for d in dirs: os.makedirs(d, exist_ok=True) return f"{base_path}/{slug}" ``` ```python github_url = sys.argv[1] owner, repo = extract_repo_info(github_url) if not owner or not repo: print(f"Error: Could not parse GitHub URL: {github_url}") sys.exit(1) slug = create_slug(repo) base_path = "/root/.openclaw/workspace/xhs-images" output_dir = create_directory_structure(base_path, slug) files_to_create = [ (f"{output_dir}/analysis.md", generate_analysis_template(repo, owner, github_url)), (f"{output_dir}/outline-strategy-a.md", generate_outline_strategy_a(repo)), (f"{output_dir}/outline-strategy-b.md", generate_outline_strategy_b(repo)), (f"{output_dir}/outline-strategy-c.md", generate_outline_strategy_c(repo)), (f"{output_dir}/outline-strategy-d.md", generate_outline_strategy_d(repo)), (f"{output_dir}/outline-strategy-e.md", generate_outline_strategy_e(repo)), (f"{output_dir}/outline-strategy-f.md", generate_outline_strategy_f(repo)), (f"{output_dir}/xiaohongshu-post.html", generate_html_template(repo, slug)), ] for filepath, content in files_to_create: with open(filepath, 'w', encoding='utf-8') as f: f.w ...[truncated 2473 chars]- Remediation
View remediation
