T09 · Insecure Skill Coding Practices
- Location
scripts/ontology.py:104- Finding
Graph Mutations Are Persisted Without Schema Validation
- Content
View full analysis
dict: """Create a new entity.""" entity_id = entity_id or generate_id(type_name) timestamp = datetime.now(timezone.utc).isoformat() entity = { "id": entity_id, "type": type_name, "properties": properties, "created": timestamp, "updated": timestamp } record = {"op": "create", "entity": entity, "timestamp": timestamp} append_op(graph_path, record) return entity ``` Updates and relations similarly persist unvalidated data: ```python def update_entity(entity_id: str, properties: dict, graph_path: str) -> dict | None: """Update entity properties.""" entities, _ = load_graph(graph_path) if entity_id not in entities: return None ...[truncated 5736 chars]- Remediation
View remediation
