T09 · Insecure Skill Coding Practices
- Location
scripts/meeting_minutes.py:166- Finding
Untrusted Meeting Content Is Written to Markdown Without Escaping
- Content
View full analysis
- Remediation
View remediation
`, and HTML entities if generated reports may be opened in renderers that support embedded HTML. 3. Consider implementing a dedicated helper that applies the same sanitization policy to every dynamic field: ```python def escape_markdown(value: object) -> str: text = str(value) text = text.replace("&", "&") text = text.replace("<", "<").replace(">", ">") return re.sub(r'([\\`*_{}\[\]()#+.!|~-])', r'\\\1', text) ``` 4. Apply the helper at the output boundary rather than relying only on extraction logic: ```python safe_topic = escape_markdown(topic) minutes += f"- **Meeting topic**: {safe_topic}\n" for point in key_points: minutes += f"- {escape_markdown(point)}\n" ``` 5. If links must be preserved, use an allowlist-based sanitizer that permits only explicitly required Markdown constructs and safe URL schemes. 6. Document that generated reports contain data derived from the input file and recommend opening them in a renderer configured to disable raw HTML and automatic remote-resource loading. 7. Add regression tests using remote-image syntax, HTML tags, nested links, headings, block quotes, and multiline payloads to ensure they are rendered as inert text. ]]>
