T09 · Insecure Skill Coding Practices
- Location
scripts/page_analyzer.py:20- Finding
Authenticated Administration Page HTML Is Sent to External LLM Services with Incomplete Redaction
- Content
View full analysis
str: """脱敏:移除 script/style、常见 token 模式,压缩空白。""" html = re.sub(r"]*>[\s\S]*?", "", html, flags=re.IGNORECASE) html = re.sub(r"]*>[\s\S]*?", "", html, flags=re.IGNORECASE) for pat, repl in _TOKEN_PATTERNS: html = pat.sub(repl, html) html = re.sub(r"\s+", " ", html).strip() return html def _get_page_summary(page) -> str: """获取页面内容摘要:URL + 脱敏后的简化 HTML。""" try: url = page.url html = page.content() html = _sanitize_html(html) if len(html) > MAX_HTML_CHARS: html = html[:MAX_HTML_CHARS] + "\n...[已截断]" return f"URL: {url}\n\nHTML(简化):\n{html}" except Exception as e: return f"获取页面失败: {e}" ``` ```python client = OpenAI(api_key=key or "ollama", base_url=url) try: resp = client.chat.completions.create( model=model, messages=[{"role": "user", "content": prompt}], temperature=0.1, ) ``` ```python page_content = _get_page_summary(page) prompt = ANALYZER_PROMPT.format(page_content=page_content) if context: prompt = f"上下文:{context}\n\n{prompt}" raw = _call_openai(prompt, api_key, base_url) ``` ### Technical Analysis Browser mode captures the complete DOM seri ...[truncated 2386 chars]- Remediation
View remediation
