T09 · Insecure Skill Coding Practices
- Location
scripts/generate-image.js:116- Finding
Unescaped Template Variables Permit Active HTML and Script Injection
- Content
View full analysis
{ return data[key] !== undefined ? data[key] : ''; }); return result; } // Build full HTML document function buildHTML(bodyContent, css) { return ` ${css} body { margin: 0; } ${bodyContent} `; } ``` The resulting document is loaded into Chromium without disabling scripts: ```javascript await page.setContent(html, { waitUntil: 'networkidle' }); ``` Representative template sinks include: ```html{{CONTENT}}``` ```html{{REFLECTIONS_CONTENT}}``` ### Technical Analysis The custom Mustache-style renderer inserts every variable directly into the HTML document without context-sensitive encoding. Consequently, values intended to represent plain text can terminate their surrounding HTML context and introduce arbitrary markup. Inputs can originate from direct user content, journal files, or chat-session records. An attacker who can influence any rendered value can supply payloads containing elements such as `- Remediation
View remediation
`, `"`, and `'`. 2. Implement context-specific encoding for values inserted into text, attributes, URLs, and CSS classes. 3. Introduce a separate explicit syntax or field type for trusted rich HTML. 4. Sanitize permitted rich HTML with a maintained allowlist sanitizer. Remove scripts, event-handler attributes, iframes, objects, embeds, unsafe SVG, dangerous URL schemes, and external resource references. 5. Disable JavaScript in the rendering page where possible: ```javascript await page.setJavaScriptEnabled(false); ``` 6. Add request interception and reject every network request except explicitly approved local resources. 7. Apply a restrictive Content Security Policy, for example by denying scripts, frames, objects, and network connections. 8. Validate input length and structure before rendering to reduce denial-of-service risks. 9. Add regression tests using payloads in every template field, including nested arrays and rich-content fields. ]]>
