T09 · Insecure Skill Coding Practices
- Location
scripts/cn_diff_checker.py:42- Finding
Terminal Escape-Sequence Injection Through Untrusted Diff Content
- Content
View full analysis
- Remediation
View remediation
= 0x20 else f'\\x{ord(char):02x}' for char in value ) def render(value, color=''): value = safe_terminal_text(value) if color and sys.stdout.isatty(): return f"{color}{value}{RESET}" return value ``` All vulnerable output paths should use `safe_terminal_text()` or `render()` rather than printing input-derived values directly. ]]>
