T09 · Insecure Skill Coding Practices
- Location
index.js:302- Finding
Stored JavaScript Injection in Generated HTML Reports
- Content
View full analysis
{ const typeLabel = { numeric: '数值', categorical: '分类', datetime: '时间', text: '文本', boolean: '布尔', empty: '空列', }[c.type] || `${c.type}`; const missingCell = c.missing_pct > 20 ? `${c.missing_pct}%` : c.missing_pct > 0 ? `${c.missing_pct}%` : `0%`; return `${c.name}${typeLabel} ${missingCell} ${c.unique.toLocaleString()} ${c.sample.join(" / ")} `; }) .join(""); const insightItems = insights .map((ins) => { const color = ins.level === "warning" ? "#fff3e0" : "#e8f4fd"; const border = ins.level === "warning" ? "#ffa940" : "#4e9bff"; return `${ins.icon} ${ins.text}`; }) .join(""); const chartDivs = charts .map((chart, i) => { const option = buildEChartsOption(chart); if (!option) return ""; const optionJson = JSON.stringify(option); return `- Remediation
View remediation
`, `"`, and `'`. 2. Treat filenames, requirements, column names, cell samples, insight text, chart labels, and type labels as untrusted input. 3. Do not interpolate serialized objects directly into executable inline scripts. 4. Place chart configuration in an `application/json` element or separate JSON file, parse it with `JSON.parse()`, and escape characters significant to the HTML parser. At minimum, replace `<`, `>`, `&`, U+2028, and U+2029 with Unicode escapes before embedding. 5. Prefer creating report elements through safe DOM APIs and assigning untrusted strings with `textContent`. 6. Add a restrictive Content Security Policy. Avoid `unsafe-inline`; move scripts to a reviewed local file or use hashes/nonces. 7. Add regression tests using payloads in filenames, requirements, column names, and cell values, including HTML event handlers and `` sequences. 8. Consider bundling ECharts locally so that a restrictive network policy can be applied to generated reports. ]]>
