T09 · Insecure Skill Coding Practices
- Location
references/report-template-pro.html:239- Finding
Unescaped User-Controlled Content in Generated HTML Reports
- Content
View full analysis
__project_name____one_line_summary__
``` ```html __info_item____info_value____info_source__ ``` ```html L1 __l1_name____l1_score____l1_note__ ``` ```html 1 __challenge__ __level__ __concern__ ``` The same advisor row pattern is repeated for all five advisors at lines 517-537. ```html P0 __point__ __impact__ __cost__ __solution__ ``` ```html- __owner__ completes __deliverable__ by __deadline__
``` The Skill instructs the host to copy and open HTML assets in a browser when embedding is unavailable: ```markdown - Host support permitting, embed it; otherwise copy the asset and open it in a browser. ``` ### Technical Analysis The HTML template contains placeholders populated from report data, including values derived from user-controlled fields such as the project name, positioning, and other intake information. No instruction requires contextual HTML encoding, sanitization, or strict validation before these values are su ...[truncated 2433 chars]- Remediation
View remediation
`, `"`, and `'` before inserting untrusted values into HTML. - Apply encoding at the final rendering boundary rather than relying on prior input processing. 2. **Use context-specific validation** - Permit only numeric values for scores, percentages, SVG coordinates, and gauge offsets. - Map CSS classes such as decision and risk styles through a fixed allowlist. - Reject arbitrary values in class, style, SVG, and other attribute contexts. 3. **Prefer safe DOM construction** - Build reports with DOM APIs and assign untrusted values through `textContent`. - Set validated numeric and enumerated attributes explicitly with `setAttribute`. - Avoid raw string concatenation and unrestricted placeholder replacement. 4. **Add a restrictive Content Security Policy** - For a self-contained report, use a policy such as: ```html ``` - If additional resources become necessary, allow only explicitly trusted origins. - Do not permit inline scripts or event handlers. 5. **Sandbox embedded reports** - If the host embeds the report in an iframe, omit `allow-scripts` unless scripts are essential. - Use a unique or opaque origin so report content cannot access host-origin data. 6. **Add security regression tests** - Test every placeholder with payloads including: ```html"> ``` - Verify that payloads appear only as visible text and never create executable DOM nodes. ]]>
