T09 · Insecure Skill Coding Practices
- Location
scripts/compress.py:155- Finding
Full File Contents May Be Disclosed to a Third-Party Model Despite Sensitive-Path Filtering
- Content
View full analysis
bool: # Resolve and validate path filepath = filepath.resolve() MAX_FILE_SIZE = 500_000 # 500KB if not filepath.exists(): raise FileNotFoundError(f"File not found: {filepath}") if filepath.stat().st_size > MAX_FILE_SIZE: raise ValueError(f"File too large to compress safely (max 500KB): {filepath}") # Refuse files that look like they contain secrets or PII. Compressing ships # the raw bytes to the Anthropic API — a third-party boundary — so we fail # loudly rather than silently exfiltrate credentials or keys. Override is # intentional: the user must rename the file if the heuristic is wrong. if is_sensitive_path(filepath): raise ValueError( f"Refusing to compress {filepath}: filename looks sensitive " "(credentials, keys, secrets, or known private paths). " "Compression sends file contents to the Anthropic API. " "Rename the file if this is a false positive." ) print(f"Processing: {filepath}") if not should_compress(filepath): print("Skipping (not natural language)") return False original_text = filepath.read_text(errors="ignore") ``` The file content is subsequently embedded into the model prompt: ```python def build_compress_prompt(original: str) -> str: return f""" Compress this markdown into caveman format. STRICT RULES: - Do NOT modify anything inside ``` code blocks - Do NOT modify anything inside inline backticks - Preserve ALL URLs exactly - Preserve ALL headings exactly - Preserve file paths and commands - Return ONLY the compressed markdown body — do NOT wrap the entire output in a ```markdown fence or any other fence. Inner code block ...[truncated 4337 chars]- Remediation
View remediation
