T03 · Remote Payload Retrieval and Execution
- Location
skills/report/SKILL.md:80- Finding
Remote Third-Party JavaScript Executes Within Sensitive Health Reports
- Content
View full analysis
健康报告 - {生成日期} ``` ### Technical Analysis The report skill collects patient profile, biochemical, imaging, medication, radiation, allergy, symptom, surgery, and discharge information before generating an HTML report. The generated document then downloads and executes JavaScript from three external CDN origins. The Tailwind URL has no explicit version, while the Lucide URL deliberately uses the mutable `latest` release. None of the resources includes a Subresource Integrity hash. Therefore, the effective code executed when a report is opened can change after the skill has been reviewed. Remote scripts execute in the report's browser document and can access its DOM, including embedded medical information. If a CDN, upstream package, maintainer account, DNS route, or delivery infrastructure is compromised, malicious JavaScript could read the report and issue outbound requests containing its contents. The behavior is not required at this privilege level. Health reports can use locally bundled, reviewed assets or static styles and charts without granting mutable third-party code access to sensitive report content. ### Attack Path 1. A user invokes the report skill. 2. The skill reads local health records and embeds selected patient information in an HTML report. 3. The user opens the generated report in a browser. 4. The browser requests scripts from `cdn.tailwindcss.com`, `cdn.jsdelivr.net`, and `unpk ...[truncated 927 chars]- Remediation
View remediation
