T09 · Insecure Skill Coding Practices
- Location
_test-template.py:37- Finding
Predictable Test Database Paths Can Overwrite and Delete Existing Files
- Content
View full analysis
Vulnerability Details
File Location:
_test-template.py, lines 37-39, 425-449, 463-494, 506-528, and 535-555
Vulnerability Type: Unsafe use and deletion of predictable filesystem paths
Risk Level: MediumThe test suite creates SQLite databases under a shared external workspace using fixed filenames. After each test, it unconditionally deletes the selected file if it exists.
Vulnerable Code
Workspace and data-directory selection:
python WORKSPACE = Path(os.environ.get("FUTURE_WORKSPACE", "/root/.openclaw/workspace-future")) DATA_DIR = WORKSPACE / "data" DATA_DIR.mkdir(exist_ok=True)Tier-gating test:
python def test_tier_gate(r: TestResult): """Test tier gating logic.""" db_path = DATA_DIR / "test-template-tier.db" conn = init_db(db_path) cur = conn.cursor() # Test operations omitted conn.close() if db_path.exists(): db_path.unlink()Analytics test:
python def test_analytics(r: TestResult): """Test analytics engine.""" db_path = DATA_DIR / "test-template-analytics.db" conn = init_db(db_path) cur = conn.cursor() # Test operations omitted conn.close() if db_path.exists(): db_path.unlink()Persistence test:
python def test_db_persistence(r: TestResult): """Test database operations.""" db_path = DATA_DIR / "test-template-persist.db" conn = init_db(db_path) cur = conn.cursor() # Test operations omitted conn.close() if db_path.exists(): db_path.unlink()Follow-up test:
python def test_follow_up_pipeline(r: TestResult): """Test follow-up sequence scheduling.""" db_path = DATA_DIR / "test-template-followup.db" conn = init_db(db_path) cur = conn.cursor() # Test operations omitted conn.close() if db_path.exists(): db_path.unlink()Tech
...[truncated 2275 chars]
- Remediation
View remediation
Remediation Suggestions
-
Create a unique temporary directory for every test run:
python import tempfile from pathlib import Path with tempfile.TemporaryDirectory(prefix="test-template-") as temp_dir: db_path = Path(temp_dir) / "tier.db" conn = init_db(db_path) try: # Run the test pass finally: conn.close() -
Prefer an in-memory SQLite database when filesystem persistence is not specifically under test:
python conn = sqlite3.connect(":memory:") -
For persistence tests, use
tempfile.NamedTemporaryFile()or a unique UUID-based path inside a private temporary directory. -
Never unlink a path merely because it exists. Track whether the current process created the file, and only remove artifacts owned by the current test run.
-
Create temporary directories with restrictive permissions and avoid shared or privileged workspace locations.
-
Use
try/finallyor context managers so database connections and temporary resources are safely cleaned up even when assertions or database operations fail. -
Avoid the hard-coded
/root/.openclaw/workspace-futuredefault for tests. Test artifacts should not be written to an application data directory or require elevated privileges.
-
