Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .jules/sentinel.md
Original file line number Diff line number Diff line change
Expand Up @@ -14,3 +14,7 @@
**Vulnerability:** A script created temporary files at predictable paths (`/tmp/wiki_claude_{session_id}.txt`) allowing potential local attackers to execute a symlink attack or view sensitive session content.
**Learning:** Hardcoded predictable temporary file paths, especially those derived from predictable elements like session_ids, expose local file operations to race conditions.
**Prevention:** Always use secure temporary file creation APIs like Python's `tempfile.NamedTemporaryFile` or Bash's `mktemp`, and pass the dynamically generated file path between components rather than assuming predictable names.
## 2026-10-18 - SQL injection in wiki-daily-digest
**Vulnerability:** Bash variables containing single quotes could break out of SQL query boundaries when interpolated directly into `sqlite3` commands.
**Learning:** Direct string interpolation in bash to SQL allows SQL injection. SQLite allows escaping single quotes by doubling them.
**Prevention:** Escape single quotes in bash variables via parameter expansion (e.g., `${var//\'/\'\'}`) before interpolating them into sqlite3 query strings.
4 changes: 2 additions & 2 deletions bin/wiki-daily-digest
Original file line number Diff line number Diff line change
Expand Up @@ -139,7 +139,7 @@ _extract_session_content() {
SELECT json_extract(p.data, '$.text')
FROM part p
JOIN message m ON p.message_id = m.id
WHERE m.session_id = '$session_id'
WHERE m.session_id = '${session_id//\'/\'\'}'
AND json_extract(m.data, '$.role') = 'assistant'
AND json_extract(p.data, '$.type') = 'text'
AND length(json_extract(p.data, '$.text')) > 20
Expand Down Expand Up @@ -175,7 +175,7 @@ _extract_goose_content() {
content="$(sqlite3 "$GOOSE_DB" "
SELECT substr(m.content_json, 1, 2000)
FROM messages m
WHERE m.session_id = '$session_id'
WHERE m.session_id = '${session_id//\'/\'\'}'
AND m.role = 'assistant'
ORDER BY m.created_at ASC;" 2>/dev/null | python3 -c "
import sys, json
Expand Down
Loading