T09 · Insecure Skill Coding Practices
- Location
lib/storage.py:25- Finding
Sensitive Financial Records Are Created Without Restrictive Permissions
- Content
View full analysis
Dict[str, Any]: try: with open(self.income_file) as f: return json.load(f) except: return {"currency": "UZS", "income": []} def _save_income(self, data: Dict[str, Any]): with open(self.income_file, 'w') as f: json.dump(data, f, indent=2, ensure_ascii=False) ``` ```python # lib/goals.py:22-26, 44-46 if data_dir is None: data_dir = Path.home() / ".finance-tracker" self.data_dir = Path(data_dir) self.data_dir.mkdir(parents=True, exist_ok=True) def _save(self, data: Dict[str, Any]): with open(self.goals_file, 'w') as f: js ...[truncated 2380 chars]- Remediation
View remediation
