T09 · Insecure Skill Coding Practices
- Location
scripts/dsl_builder.py:172- Finding
Unescaped Input Allows DSL and R2RML Mapping Injection
- Content
View full analysis
str: """Generate custom DSL format.""" output = f"""mapping: {self.name} version: {self.version} description: {self.description or 'Auto-generated mapping'} source: type: {self.source.source_type.value if self.source else 'unknown'} location: {self.source.location if self.source else 'not defined'} """ if self.source.table_name: output += f" table: {self.source.table_name}\n" output += "\nentities:\n" for entity_id, entity in self.entities.items(): output += f""" - entity_id: {entity_id} type: {entity.entity_type} identifier: {entity.identifier_column} uri_template: "{entity.uri_template}" properties: """ for prop in entity.properties: output += f""" - source: {prop.source_column} predicate: {prop.target_predicate} type: {prop.datatype} """ ``` ```python def to_r2rml(self) -> str: """Generate R2RML Turtle format.""" output = """@prefix rr: . @prefix foaf: . @prefix schema: . @prefix ex: . @prefix xsd: . """ for entity_id, entity in self.entities.items(): entity_name = entity_id.replace("_", " ").title().replace(" ", "") output += f"ex:{entity_name}Mapping a rr:TriplesMap ;\n" if self.source and self.source.table_name: output += f' rr:logicalTable [ rr:tableName "{self.source.table_name}" ] ;\n' output += f""" rr:subjectMap [ rr:template "{entity.uri_template}" ; rr:class {entity.entity_type} ] ; """ for prop in entity.properties: o ...[truncated 4299 chars]- Remediation
View remediation
