T09 · Insecure Skill Coding Practices
- Location
scripts/report_generator.py:105- Finding
Stored HTML and Script Injection in Generated Reports
- Content
View full analysis
{text}' ``` Report fields are obtained without sanitization or contextual encoding: ```python def generate_report(data: dict) -> str: name = safe_get(data, "name", "未命名产品") category = safe_get(data, "category", "未指定行业") now = datetime.now().strftime("%Y年%m月%d日 %H:%M") scores = safe_get(data, "scores", {}) score_result = calculate_total_score(scores) market = safe_get(data, "market_demand", {}) user = safe_get(data, "user_profile", {}) pain = safe_get(data, "pain_points", {}) competitors = safe_get(data, "competition", {}) monetization = safe_get(data, "monetization", {}) acquisition = safe_get(data, "acquisition", {}) marketing = safe_get(data, "marketing", {}) cost = safe_get(data, "cost_structure", {}) tech = safe_get(data, "tech_feasibility", {}) risks = safe_get(data, "risks", {}) ``` Those values are then interpolated directly into the generated document: ```python html = f""" SaaS可行性决策报告 - {name} ...``` Market research values and list entries are also inserted without escaping: ```python mkt_score = s ...[truncated 4077 chars]☁️ {name}
{category}SaaS 产品可行性决策报告{now}- Remediation
View remediation
str: return escape(str(value), quote=True) ``` Use this helper for product names, categories, descriptions, trends, list entries, table cells, persona fields, competitor data, strategies, risks, and all other externally derived values. 2. Do not use encoding alone for values inserted into CSS or other non-text contexts. Validate such values against strict allowlists. Colors should only come from predefined constants. 3. Validate numeric fields before using them in calculations or style attributes: ```python import math def validated_score(value, default=50): try: score = float(value) except (TypeError, ValueError): return default if not math.isfinite(score): return default return max(0, min(100, score)) ``` 4. Prefer a template engine configured with automatic HTML escaping rather than assembling large HTML documents through f-strings. 5. Add a restrictive Content Security Policy to provide defense in depth. For a self-contained report without JavaScript, an appropriate starting point is: ```html ``` 6. Add regression tests covering at least: - `` - `` - SVG event handlers - Iframes and external resource references - Quotes and angle brackets in every report field - Malformed, negative, oversized, infinite, and nonnumeric score values 7. Treat all WebSearch and WebFetch content as untrusted. Preserve it as plain text and never allow source markup to pass directly into the generated report. ]]>
