T09 · Insecure Skill Coding Practices
- Location
scripts/maintenance.py:49- Finding
Broad Automatic Git Staging Can Publish Sensitive Local Data
- Content
View full analysis
bool: """自动提交所有变更""" if not has_changes(): print("✅ 无变更,跳过提交") return False version = get_version() summary = f"auto: v{version} 定时维护" run(["git", "add", "-A"]) run(["git", "commit", "-m", summary, "--allow-empty"]) print(f"📦 已提交: {summary}") return True def auto_push() -> bool: """推送到 GitHub""" if not os.environ.get("ALLOW_AUTO_PUSH"): print("⏭️ 跳过推送 (设置 ALLOW_AUTO_PUSH=1 以启用)") return False r = run(["git", "push", "origin", "master", "--no-verify"], check=False) if r.returncode == 0: print(f"🚀 已推送到 GitHub") return True else: print(f"⚠️ 推送失败: {r.stderr[:200]}") return False def auto_publish(): """发布到 ClawHub""" if not os.environ.get("ALLOW_AUTO_PUBLISH"): print("⏭️ 跳过 ClawHub 发布 (设置 ALLOW_AUTO_PUBLISH=1 以启用)") return False version = get_version() today = datetime.now().strftime("%Y-%m-%d") r = run(["clawhub", "publish", ".", "--slug", "fu-mu-gong-ke", "--name", "父母的功课", "--version", version, "--changelog", f"auto: v{version} ({today})"], check=False) ``` ```python committed = auto_commit() if not committed: return auto_push() auto_publish() ``` ### Technical Analysis The maintenance workflow executes `git add -A`, which stages every modified, deleted, and untracked file under the repository rather than restricting staging to an approved source-file allowlist. It then commits the complete staged set without presenting the staged file list for approval. When `ALLOW_AUTO_PUSH` is set, the resulting commit is pushed to the configured `origin` remote. When `ALLOW_AUTO_PUBLISH` is set, the ...[truncated 2739 chars]- Remediation
View remediation
