T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_trending.py:142- Finding
Untrusted GitHub Repository Descriptions Enter the Agent and Markdown Pipelines Without Sanitization
- Content
View full analysis
dict[str, Any]: full_name = repo.get("repo") author = None name = None if isinstance(full_name, str) and "/" in full_name: author, name = full_name.split("/", 1) description = repo.get("description") language = repo.get("language") title = title_from_description(description) english_description = description if is_english_text(description) else None repo["full_name"] = full_name repo["author"] = author repo["name"] = name repo["author_avatar"] = f"https://github.com/{author}.png" if author else None repo["title"] = title repo["title_en"] = title if is_english_text(title) else None repo["summary"] = truncate(description) repo["summary_en"] = truncate(english_description) repo["primary_lang"] = language repo["lang_color"] = LANGUAGE_COLORS.get(language) if updated_at is not None: repo["updated_at"] = updated_at return repo ``` The description is also inserted into Markdown with only pipe and newline escaping: ```python def escape_markdown_cell(value: Any) -> str: if value is None: return "-" return str(value).replace("|", "\\|").replace("\n", " ") ``` ```python for repo in report["repositories"]: lines.append( "| {rank} | {repo} | { ...[truncated 3790 chars]- Remediation
View remediation
