T01 · Skill Instruction Hijacking
- Location
builder/orchestrator.py:81- Finding
Untrusted Notion Records Are Passed to a Bash-Enabled Coding Agent
- Content
View full analysis
List[Dict]: """Notion에서 "개발중" 상태인 프로젝트 조회""" if not self.token: return [] try: query_data = { "filter": { "property": "상태", "status": {"equals": "개발중"} } } req = urllib.request.Request( f"{self.api_base}/databases/{self.database_id}/query", data=json.dumps(query_data).encode('utf-8'), headers=self.headers ) with urllib.request.urlopen(req, timeout=10) as response: result = json.loads(response.read().decode()) projects = [] for page in result.get('results', []): projects.append(self._parse_page(page)) return projects except Exception as e: logger.warning("Failed to query Notion: %s", e) return [] def _parse_page(self, page: Dict) -> Dict: """Notion 페이지를 ProjectIdea 형식으로 파싱""" props = page.get('properties', {}) title = "" if '내용' in props and 'title' in props['내용']: titles = props['내용']['title'] if titles: title = titles[0].get('text', {}).get('content', '') description = "" if '도구 설명' in props and 'rich_text' in props['도구 설명']: texts = props['도구 설명']['rich_text'] if texts: description = texts[0].get('text', {}).get('content', '') url = "" if 'URL' in props and 'url' in props['URL']: url = props['URL']['url'] return { 'title': title, 'description': description, 'url': url, 'notion_page_id': page['id'] } ``` ```pytho ...[truncated 4388 chars]- Remediation
View remediation
