T09 · Insecure Skill Coding Practices
- Location
scripts/generate_report.py:263- Finding
Stored HTML and JavaScript Injection in Generated Reports
- Content
View full analysis
财经日报 — {report_date} ``` ```javascript- Remediation
View remediation
`, `&`, U+2028, and U+2029, or place the data in a non-executable JSON element: ```python data_json = json.dumps(report_data, ensure_ascii=False, default=str) data_json = ( data_json.replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` 4. Replace `innerHTML` with `textContent` and explicit DOM construction for all remote or user-controlled values. 5. Add a restrictive Content Security Policy. Avoid allowing inline scripts if practical; otherwise use a generated nonce or script hash. 6. Add regression tests containing payloads such as closing script tags, HTML event handlers, quotation marks, ampersands, and Unicode line separators. Verify that these payloads appear only as text and never execute. ]]>
