T09 · Insecure Skill Coding Practices
- Location
scripts/ceae_tree_export.py:51- Finding
Unbounded JSON content and rendering dimensions enable resource exhaustion
- Content
View full analysis
dict[str, Any]: if not path.is_file(): raise TreeValidationError(f"Input file does not exist: {path}") try: value = json.loads(path.read_text(encoding="utf-8-sig")) except (OSError, json.JSONDecodeError) as exc: raise TreeValidationError(f"Cannot read valid JSON from {path}: {exc}") from exc if not isinstance(value, dict): raise TreeValidationError("Top-level JSON value must be an object") return value ``` ```python def optional_text(value: Any, field: str, identifier: str) -> str: if value is None: return "" if isinstance(value, list): value = "; ".join(str(item) for item in value) if not isinstance(value, str): raise TreeValidationError(f"Node {identifier!r} {field!r} must be text or an array") return " ".join(value.replace("\x00", " ").split()) ``` ```python def wrap_label(node: FlatNode) -> str: label = "\n".join( textwrap.wrap(node.label, width=WRAP_WIDTH, break_long_words=False, break_on_hyphens=False) ) if node.evidence: label += f"\nEvidence: {node.evidence}" return label ``` ```python figure_width = min(MAX_FIGURE_INCHES, max(12.0, x_span + 4.0)) figure_height = min(MAX_FIGURE_INCHES, max(8.0, y_span + 5.0)) ``` ```python def validate_output(path: Path, force: bool, dpi: int) -> None: if path.suffix.lower() != ".png": raise TreeValidationError("Output path must use the .png suffix") if path.exists() and not force: raise TreeValidationError(f"Refusing to replace existing output without --force: {path}") if not 72 <= dpi <= 600: raise TreeValidationError(" ...[truncated 3648 chars]- Remediation
View remediation
