T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/format.py:284- Finding
Overbroad Home-Directory Search Can Copy Sensitive Local Files into Publication Artifacts
- Content
View full analysis
str: """把 Obsidian ![[image.jpg]] 转为标签,复制图片到输出目录""" images_dir = output_dir / "images" # 搜索路径:vault 目录(如需额外图片目录,在 config.json 的 image_search_paths 中配置) search_roots = [vault_root] # 支持自定义图片搜索目录 config_path = SKILL_DIR / "config.json" if config_path.exists(): import json as _json try: _cfg = _json.load(open(config_path, encoding="utf-8")) for p in _cfg.get("image_search_paths", []): search_roots.append(Path(p).expanduser()) except Exception: pass def replace_img(match): filename = match.group(1).strip() # 处理带尺寸的 wikilink: ![[image.jpg|300]] if "|" in filename: filename = filename.split("|")[0].strip() # 在多个目录中搜索图片(followlinks=True 跟随符号链接) for search_root in search_roots: if not search_root.exists(): continue for root, dirs, files in os.walk(search_root, followlinks=True): if filename in files: img_path = Path(root) / filename images_dir.mkdir(parents=True, exist_ok=True) dest = images_dir / filename if not dest.exists(): shutil.copy2(img_path, dest) # 返回占位标记,后面注入样式时处理 return f'
' return f'[图片: {filename}]' return re.sub(r"!\[\[([^\]]+)\]\]", replace_img, text) ``` ### Technical Analysis The configured vault ...[truncated 2327 chars]- Remediation
View remediation
