T09 · Insecure Skill Coding Practices
- Location
references/generate-api-client.sh:57- Finding
OpenAPI Input Can Inject Executable TypeScript into the Generated API Client
- Content
View full analysis
/dev/null | \ sed 's/.*title:[[:space:]]*"\([^"]*\)".*/\1/;s/.*title:[[:space:]]*'\''\([^'\'']*\)'\''.*/\1/;s/.*title:[[:space:]]*\(.*\)/\1/' | \ sed 's/[[:space:]]*$//') if [ -z "$PROJECT_TITLE" ]; then PROJECT_TITLE="$(basename "$YAML_FILE" .yaml)" fi cat << END_HEADER /** * ⚠️ 本文件由 OpenAPI 契约自动生成,前端 agent 禁止手改。 * 新增端点流程:改 standards/{project}-openapi.yaml → 重新运行 generate-api-client.sh → 两端同步。 * * 项目: ${PROJECT_TITLE} * 生成时间: $(date '+%Y-%m-%d %H:%M:%S') * 源文件: ${YAML_FILE} * 生成命令: * bash references/generate-api-client.sh ${YAML_FILE} */ ``` Additional OpenAPI-derived fields are directly concatenated into TypeScript: ```awk # New group if (group != prev_group) { if (prev_group != "") printf "};\n\n" printf "export const %s = {\n", group prev_group = group } # JSDoc comment if (summary != "") printf " /** %s */\n", summary if (sig_parts != "") { printf " %s: (%s) =>\n request<%s>(%s),\n", op_id, sig_parts, resp_type, req_args } else { printf " %s: () =>\n request<%s>(%s),\n", op_id, resp_type, req_args } ``` ### Technical Analysis The generator treats the OpenAPI document as trusted source code rather than untrusted structured data. The project title, tags, operation IDs, summaries, paths, schema names, response types, and parameter names are incorporated into generated TypeScript through shell heredocs and `awk` formatting. No contextual escaping or strict identifier validation is applied: - Comment content is not protected against `*/` comment termination. - TypeScript identifiers are not restricted to valid identifier syntax. - Path and request strings are placed inside ...[truncated 2351 chars]- Remediation
View remediation
