T09 · Insecure Skill Coding Practices
- Location
scripts/portfolio.py:30- Finding
Portfolio File Created Without Explicit Restrictive Permissions
- Content
View full analysis
dict: """加载持仓数据""" if PORTFOLIO_FILE.exists(): with open(PORTFOLIO_FILE, "r", encoding="utf-8") as f: return json.load(f) return {"positions": [], "updated_at": None} def save_portfolio(data: dict): """保存持仓数据""" PORTFOLIO_FILE.parent.mkdir(parents=True, exist_ok=True) data["updated_at"] = datetime.now().isoformat() with open(PORTFOLIO_FILE, "w", encoding="utf-8") as f: json.dump(data, f, ensure_ascii=False, indent=2) ``` ### Technical Analysis The portfolio file stores financial information including stock identifiers, acquisition costs, quantities, names, and timestamps. The application creates the containing directories and file without explicitly setting restrictive permissions. Consequently, permissions are determined by the process umask and any permissions already present on the parent directories or portfolio file. In an environment with a permissive umask or incorrectly configured home-directory permissions, the resulting `portfolio.json` may be readable by other local users. Opening an existing file with mode `"w"` does not correct insecure permissions already assigned to that file. The implementation also writes directly to the destination rather than creating a securely permissioned temporary file and atomically replacing the original. ### Attack Path 1. A user runs `portfolio.py add`, `portfolio.py update`, or `portfolio.py analyze`, causing `save_portfolio()` to create or update the portfolio file. 2. The process executes under a permissive umask, or the portfolio file already has group-readable or world-readable permissions. 3. Another local accou ...[truncated 962 chars]- Remediation
View remediation
