T09 · Insecure Skill Coding Practices
- Location
scripts/lib/trip-artifact.mjs:48- Finding
Arbitrary JavaScript Execution During HTML Artifact Validation
- Content
View full analysis
"); process.exit(2); } ``` ### Technical Analysis The parser treats ...[truncated 2585 chars]- Remediation
View remediation
{ "tripMeta": {}, "tripDays": [] } ``` Parse the content exclusively with `JSON.parse()`. 2. Remove both `Function` and `new Function` from the artifact-loading path. 3. If compatibility with JavaScript object syntax is mandatory, parse the source into an AST without evaluating it. Recursively allow only: - Plain object properties with static keys. - Arrays. - String, number, Boolean, and null literals. Explicitly reject calls, member access, getters, setters, methods, computed properties, templates, spread syntax, identifiers, assignments, and function expressions. 4. Validate parsed data against `schemas/trip-data.schema.json` after inert parsing. 5. Add regression tests containing side-effecting initializers and verify that validation rejects them without executing any expression. 6. Run artifact parsing in a least-privileged isolated process as defense in depth. The process should have no secrets, unnecessary filesystem write access, or unrestricted network access. ]]>
