T09 · Insecure Skill Coding Practices
- Location
scripts/analyzer_generic.py:188- Finding
Untrusted CSV Content Is Embedded Verbatim into an AI-Consumed Markdown Report
- Content
View full analysis
- Remediation
View remediation
", ">") return text[:500] ``` Use the function at every report interpolation point: ```python safe_name = escape_markdown_cell(row["name"]) report.append( f"| {i + 1} | {safe_name} | {row['roi']:.2f} | " f"{row['ctr']:.2%} | {row['cvr']:.2%} | " f"{row['spend']:.2f} | {row['revenue']:.2f} |" ) ``` 2. **Preserve the trust boundary for downstream AI processing** Pass report data to the AI in a structured data field rather than combining it with instructions. Explicitly identify CSV-derived values as untrusted data that must never be treated as commands. 3. **Prefer structured serialization** Generate JSON containing separately typed fields, and let a trusted rendering layer create Markdown. This prevents data fields from changing the report's structure. 4. **Validate text fields** Reject or normalize control characters, excessive lengths, embedded NUL bytes, bidirectional-control characters, and unexpected multiline values. 5. **Disable active Markdown constructs where possible** If the report is rendered as HTML, use a sanitizer that blocks remote images, unsafe links, raw HTML, and active URI schemes. 6. **Add adversarial tests** Test names containing table delimiters, headings, links, images, HTML, multiline instructions, and Unicode control characters. Verify that each value remains confined to one inert table cell. 7. **Apply protections consistently** The direct i ...[truncated 214 chars]
