CCAPrep
← All labs
D2·Fix the code

An unsafe text editor handler

This handler implements the text editor tool. It passes tests and works in demos. Review it as though the model output were hostile — because prompt injection makes that a real possibility.

PROJECT_ROOT = Path("/srv/app")

def handle_editor(command: dict) -> str:
    path = PROJECT_ROOT / command["path"]

    if command["command"] == "view":
        return path.read_text()
    if command["command"] == "create":
        path.write_text(command["file_text"])
        return "ok"
    return "unsupported"

1.What is the vulnerability?

2.What is the correct check?