T09 · Insecure Skill Coding Practices
- Location
templates/invoice.html:108- Finding
Unescaped Stored Data in Generated HTML and Markdown Documents
- Content
View full analysis
{{n}} {{description}} {{type}} {{quantity}} {{unit_price}} {{amount}} {{currency}}Subtotal{{subtotal}} {{currency}} {{tax_name}} ({{tax_rate}}){{tax_amount}} {{currency}} Discount-{{discount_amount}} {{currency}} Total Due{{total_amount}} {{currency}}Payment Instructions{{payment_instructions}}``` The Markdown invoice uses the same direct interpolation pattern: ```markdown | {{n}} | {{description}} | {{type}} | {{quantity}} | {{unit_price}} | {{amount}} | ## Payment Instructions {{payment_instructions}} ## Notes {{notes}} ``` ### Technical Analysis The Skill automatically imports client, contract, invoice, and payment information and inserts those values directly into HTML and Markdown templates. Neither the templates nor the governing workflow require context-aware output encoding, HTML sanitization, or Markdown escaping. Fields such as `client_name`, `description`, `payment_instructions`, and `notes` can therefore alter the structure of generated documents. In HTML output, attacker-controlled value ...[truncated 1867 chars]Notes{{notes}}- Remediation
View remediation
` elements, event-handler attributes, raw HTML, malicious Markdown links, table-breaking pipes, and multiline payloads. 9. Generate PDFs through a renderer configured to disable JavaScript, local-file access, and uncontrolled remote-resource loading. ]]>
