T09 · Insecure Skill Coding Practices
- Location
scripts/init_memory.py:119- Finding
Unsanitized User Identifier Allows Path Traversal and Arbitrary File Writes
- Content
View full analysis
- Remediation
View remediation
str: if not re.fullmatch(r"[A-Za-z0-9_-]{1,64}", value): raise ValueError("Invalid user identifier") return value def contained_path(base: Path, child: str) -> Path: base = base.resolve() destination = (base / child).resolve() if not destination.is_relative_to(base): raise ValueError("Path escapes the storage directory") return destination ``` 5. Reject symbolic-link destinations or operate relative to a verified directory handle. 6. Use exclusive creation or atomic replacement where overwriting existing records is not required. 7. Run the script with a dedicated, least-privileged operating-system account. ]]>
