T09 · Insecure Skill Coding Practices
- Location
scripts/fishing_planner.py:644- Finding
Stored HTML Injection in Generated Trip Reports
- Content
View full analysis
{date[-5:] if len(date)>=10 else date}{emoji}{text_day}{temp_low}° / {temp_high}°🌬️ {wind_dir} {wind_scale}级 | 💧 {humidity}%🌧️ {precip}mm""" ``` ```python route_steps += f"""""" ``` ```python for t in fishing_score["tide_events"]: tide_rows += f""" {t['emoji']} {t['type']} {t['time']} {t['height']}m """ ``` ```python for name, status, desc in fishing_score.get("conditions", []): tag_class = {"宜": "tag-green", "可": "tag-yellow", "差": "tag-red", "禁": "tag-red", "--": "tag-gray"} tag = tag_class.get(status, "tag-gray") condition_rows += f""" {name} {status} {desc} """ ``` Additional unescaped document-level sinks include: ```python 钓鱼行程规划 - {dest_name} ``` ```python{i+1}{step['instruction']}{step['road'] or ''} · {step['distance']}km{origin_name} {mode_info['emoji']} {dest_name}``` ### Technical Analysis The report generator interpolates user-derived and remotely supplied values directly into HTML without applying HTML escaping. Relevant values include: - Formatted origin and destination names returned by the geocoding API - Route ins ...[truncated 2089 chars]- Remediation
View remediation
``` 6. Add regression tests that pass payloads such as the following through every report field and verify that they appear only as encoded text: ```html ">``` ]]>
