T09 · Insecure Skill Coding Practices
- Location
references/report-template-pro.html:505- Finding
Unescaped Dynamic Content Enables Script Injection in Generated HTML Reports
- Content
View full analysis
📝 Review Meeting Script🎯 Opening (3 min)__script_open__🔥 Core Argument (10 min)__script_core__⚠ Risk Mitigation (5 min)__script_risk__✅ Plan Selection__script_plan__``` The same unsafe placeholder pattern also appears elsewhere in the template, including the requirement name in the document title and report heading, the summary, challenges, replies, RACI entries, and action items. ### Technical Analysis The report template places dynamically generated, user-influenced values directly into HTML element content. No contextual HTML encoding, sanitization, or safe DOM assignment mechanism is specified before placeholders such as `__script_open__` and `__script_core__` are replaced. PRD content is attacker-controlled input. Generated meeting-script text can preserve or reproduce malicious markup from that content. If a placeholder is replaced with a payload such as: ```html🎤 Closing (5 min)__script_close__``` the browser interprets the result as an HTML element rather than plain report text. ...[truncated 1784 chars]
- Remediation
View remediation
`, `"`, and `'` in values intended to be plain text. 2. Prefer constructing the report through DOM APIs and assigning untrusted values with `textContent` rather than concatenating or substituting raw HTML. 3. If limited rich-text formatting is required, process content with a maintained allowlist-based sanitizer. Permit only necessary formatting elements and remove scripts, event-handler attributes, dangerous URL schemes, SVG, iframes, forms, and embedded objects. 4. Validate non-text placeholders separately: - Restrict CSS class placeholders to explicit allowlists. - Parse numeric and SVG-coordinate placeholders as finite numbers. - Reject arbitrary values in style attributes. 5. Add a restrictive Content Security Policy, for example by disallowing scripts and external content where the static report requires neither. CSP should be treated as defense in depth rather than a replacement for encoding. 6. Add regression tests covering payloads such as: - `` - `` - `` - Closing-tag payloads such as `` - `javascript:` links 7. Document a mandatory safe-rendering step in `SKILL.md` so any agent using the template knows that all PRD-derived and model-generated values must be encoded before placeholder replacement. ]]>
