T09 · Insecure Skill Coding Practices
- Location
scripts/htmlstrip.py:177- Finding
Incomplete HTML Sanitization Allows Executable Content
- Content
View full analysis
") def handle_endtag(self, tag): tag = tag.lower() if tag in self.strip_tags: self.drop_depth = max(0, self.drop_depth - 1) return self.out.append(f"") def handle_startendtag(self, tag, attrs): tag = tag.lower() if tag in self.strip_tags: return clean_attrs = [(k, v) for k, v in attrs if not k.lower().startswith("on") and k.lower() != "style"] attr_str = "".join( f' {k}="{html.escape(v, quote=True)}"' if v is not None else f" {k}" for k, v in clean_attrs ) self.out.append(f"<{tag}{attr_str} />") ``` ### Technical Analysis The HTML mode uses a denylist that removes selected tags, attributes beginning with `on`, and inline `style` attributes. All other elements and attributes are preserved. Attribute-value HTML escaping prevents direct quote-based attribute breakout, but it does not make URL-bearing attributes safe. In particular, values of attributes such as `href`, `src`, `action`, `formaction`, and `xlink:href` are not checked against an approved scheme list. A dangerous value such as `javascript:alert(1)` therefore survives sanitization. The sanitizer also permits arbitrary non-denylisted elements, including potentially active SVG, MathML, `meta`, and `base` elem ...[truncated 1621 chars]- Remediation
View remediation
