Tainted flow: 'skill_path' from input (line 296, user input) → open (file write)
Medium
- Category
- Data Flow
- Content
goal=data['goal'], ) skill_path = os.path.join(skill_dir, 'SKILL.md') with open(skill_path, 'w', encoding='utf-8') as f: f.write(skill_content) created_files.append(('SKILL.md', 'Bộ não chính của skill'))- Confidence
- 98% confidence
- Finding
- with open(skill_path, 'w', encoding='utf-8') as f:
