T09 · Insecure Skill Coding Practices
- Location
SKILL.md:8- Finding
Filesystem Access Is Broader Than the Declared Skill Permissions
- Content
View full analysis
.pre-..bak so each destructive run gets a distinct backup. Returns the backup path, or None if the source file does not exist (new/empty database). """ src = db.db_file if not src or not os.path.exists(src): return None stamp = datetime.now().strftime("%Y%m%d-%H%M%S") dst = f"{src}.pre-{label}.{stamp}.bak" shutil.copy2(src, dst) logging.info(f"Automatic backup written before destructive operation: {dst}") return dst ``` It accepts and reads arbitrary CSV and special-case JSON paths: ```python special_cases = SpecialCases(args.special_cases) if args.special_cases else None rows_added = data_parser.add_data( args.file, allow_unsettled=getattr(args, 'allow_unsettled', False) ) ``` ```python try: with open(file_path, "r", encoding="utf-8") as special_cases_file: special_cases = json.load(special_cases_file) except UnicodeDecodeError: with open(file_path, "r", encoding="cp1252") as special_cases_file: special_cases = json.load(special_cases_file) ``` ```python try: with open(file_path, "r", encoding="utf-8") as avanza_data_file: avanza_data = csv.reader(avanza_data_file, delimiter=';') avanza_header_row = next(avanza_data) new_format ...[truncated 3268 chars]- Remediation
View remediation
