T09 · Insecure Skill Coding Practices
- Location
scripts/build_cma.py:150- Finding
Stored Cross-Site Scripting in Generated Interactive CMA Report
- Content
View full analysis
``` The generated page then embeds the serialized payload directly inside an executable script and inserts untrusted comparable-property fields with `innerHTML`: ```javascript- Remediation
View remediation
... ``` Then parse its text: ```javascript const data = JSON.parse(document.getElementById("cma-data").textContent); ``` 3. **Escape HTML-significant characters before embedding JSON.** At minimum, replace `<`, `>`, and `&` with their Unicode escape forms. Escaping U+2028 and U+2029 is also advisable: ```python payload_json = json.dumps(payload, separators=(",", ":")) payload_json = ( payload_json .replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` This measure should complement, not replace, removal of unsafe `innerHTML` usage. 4. **Apply a restrictive Content Security Policy when hosting reports.** Avoid inline scripts where possible and use a policy that disallows inline event handlers and unauthorized network destinations. 5. **Add automated regression tests** that generate and inspect reports containing payloads such as: ```text"> ``` Tests should verify that these values are rende ...[truncated 94 chars]
