T09 · Insecure Skill Coding Practices
- Location
references/spec2code.md:70- Finding
Generated Strategy Code Is Executed Without a Security Sandbox or Dangerous-Operation Validation
- Content
View full analysis
/ uv run python strategy_1.py ``` If dependencies are absent, it creates an environment and installs packages before execution: ```bash cd library// uv venv && uv pip install backtrader yfinance akshare uv run python strategy_1.py ``` The validator performs syntax, structure, and Backtrader indicator checks, but it contains no policy against dangerous Python operations: ```python def validate_code(code: str) -> ValidationResult: errors: List[str] = [] warnings: List[str] = [] try: ast.parse(code) except SyntaxError as e: errors.append(f"SyntaxError at line {e.lineno}: {e.msg}") return ValidationResult(valid=False, errors=errors, warnings=warnings) tree = ast.parse(code) # Structural Backtrader checks omitted here. if _VALID_INDICATORS: invalid = _check_indicators(tree) errors.extend(invalid) return ValidationResult( valid=len(errors) == 0, errors=errors, warnings=warnings, ) ``` ### Tec ...[truncated 2473 chars]- Remediation
View remediation
