Tainted flow: 'cmd' from os.environ.get (line 145, credential/environment) → subprocess.run (code execution)
Medium
- Category
- Data Flow
- Content
cmd.extend(["--memory", memory_date]) try: result = subprocess.run( cmd, capture_output=True, text=True,- Confidence
- 83% confidence
- Finding
- result = subprocess.run( cmd, capture_output=True, text=True, cwd=str(SKILL_DIR) )
