T09 · Insecure Skill Coding Practices
- Location
scripts/sync-readme-env-table.sh:63- Finding
Markdown Injection Through Insufficiently Escaped Environment Values
- Content
View full analysis
- Remediation
View remediation
` elements and HTML-escape all untrusted values with a standard encoder such as Python's `html.escape()`. 2. If Markdown inline-code spans must be retained, calculate a backtick delimiter longer than any consecutive backtick sequence in the value, and continue escaping table delimiters appropriately. 3. Normalize or reject control characters that could disrupt the generated table structure. 4. Add regression tests covering: - Single and repeated backticks - Markdown links and images - Raw HTML tags - Pipe characters - Newlines and carriage returns - Empty values 5. Run the generator against adversarial fixtures and verify that every value renders as literal code rather than active Markdown or HTML. ]]>
