T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_content.py:117- Finding
Implicit Remote Disclosure of Document Content Through Automatically Selected LLM Provider
- Content
View full analysis
dict: """Use LLM to analyze content and generate slide structure.""" if not HAS_LLM: print("Error: LLM adapter not available") return None adapter = LLMAdapter(model=model) # Build prompt with optional user instruction prompt = ANALYZE_PROMPT.format(content=content[:50000]) # Limit content length if instruction: prompt += f""" --- ## 【用户自定义指令 — 最高优先级】 以下用户指令**覆盖**上述所有默认规则,必须严格遵守: {instruction} """ print(f"Analyzing content ({len(content)} chars)...") try: response = await adapter.generate( prompt, temperature=0.3, max_tokens=16000, timeout=300.0 # 5 minutes timeout ) ``` ```python # scripts/llm_adapter.py:67-82 def _get_default_model(self) -> str: """Get default model from environment or OpenClaw config.""" # 1. Check environment variable env_model = os.getenv("LLM_MODEL") if env_model: return env_model # 2. Check OpenClaw models.json for first available model models_config = Path.home() / ".openclaw" / "agents" / "main" / "agent" / "models.json" if models_config.exists(): try: with open(models_config, 'r') as f: config = json.load(f) providers = config.get("providers", {}) for provider_name, provider_config in providers.items(): models = provider_config.get("models", []) if models: return models[0].get("id", "glm-4-flash") except: pass ``` ```python ...[truncated 3133 chars]- Remediation
View remediation
