T09 · Insecure Skill Coding Practices
- Location
scripts/json_converter.py:51- Finding
RDF Triple Injection Through Unescaped Literals and Identifiers
- Content
View full analysis
" elif self.language_tag: obj_str = f'"{self.obj}"@{self.language_tag}' elif self.data_type: obj_str = f'"{self.obj}"^^<{self.data_type}>' else: obj_str = f'"{self.obj}"' return f"{subject_str} {predicate_str} {obj_str} ." ``` ```python if "id" in data: entity_id = data["id"] elif "name" in data: entity_id = self._slugify(str(data["name"])) elif key: entity_id = key else: data_str = json.dumps(data, sort_keys=True) entity_hash = hashlib.md5(data_str.encode()).hexdigest()[:8] entity_id = entity_hash return f"{self.base_namespace}entity_{entity_id}" ``` ```python @staticmethod def _slugify(text: str) -> str: """Convert text to slug format.""" return text.lower().replace(" ", "_").replace("-", "_") ``` ### Technical Analysis The Turtle and N-Triples serializers directly interpolate attacker-controlled literal values into quoted RDF syntax. They do not escape quotation marks, backslashes, carriage returns, line feeds, control characters, or other syntax-significant characters. Entity identifiers read from JSON are also appended directly to the base namespace. The fallback `_slugify()` function only replaces spaces and hyphens and does not encode or reject characters such as `<`, `>`, `"`, `#`, backslashes, or control characters. Consequently, both RDF literal and IRI boundaries may b ...[truncated 1985 chars]- Remediation
View remediation
