T09 · Insecure Skill Coding Practices
- Location
scripts/generate_report.py:36- Finding
Unescaped Prospect Data Allows HTML and Script Injection in Generated Reports
- Content
View full analysis
{p['name']}{p['position']}Location: {p.get('location', 'N/A')} | LinkedIn ProfileGap Analysis:
-
"""
for need in p.get('needs', []):
html += f"
- {need} " html += f"""
Pitch Idea: {p.get('pitch', 'N/A')} ``` ### Technical Analysis `generate_html()` parses JSON and directly interpolates prospect-controlled fields into an HTML document. The fields `name`, `position`, `location`, `linkedin_url`, each item in `needs`, and `pitch` are not HTML-escaped. An attacker-controlled value containing HTML, such as an image with an event handler or a closing tag followed by a script element, can break out of the intended document structure. The `linkedin_url` field is also inserted into an `href` attribute without validating its scheme, allowing dangerous values such as `javascript:` URLs. The Skill’s workflow obtains information from LinkedIn profiles and external company websites. If content derived from those sources is copied into the prospect JSON, the report generator treats that external data as trusted markup. Exploitability depends on whether the resulting HTML is opened in a browser or processed by a PDF renderer that permits JavaScript, external resource loading, or local-resource access. ### Attack Path 1. An attacker places craf ...[truncated 1446 chars]- Remediation
View remediation
javascript:alert(document.domain) ``` The tests should confirm that markup is rendered as text and that unsupported URL schemes are rejected. ]]>
