Tainted flow: 'workspace_dir' from input (line 600, user input) → shutil.copy (file write)
Medium
- Category
- Data Flow
- Content
if not args.dry_run: import shutil for f in ['IDENTITY.md', 'SOUL.md', 'AGENTS.md', 'USER.md']: shutil.copy(agent_dir / f, workspace_dir / f) log(f" 同步到工作区", 'success') # 3. 更新 openclaw.json- Confidence
- 96% confidence
- Finding
- shutil.copy(agent_dir / f, workspace_dir / f)
