T09 · Insecure Skill Coding Practices
- Location
scripts/update-grid.js:68- Finding
Unvalidated Active-Content URLs Persisted On-Chain
- Content
View full analysis
Vulnerability Details
File Location:
scripts/update-grid.js:27-31,scripts/update-grid.js:68-74
Vulnerability Type: Missing schema and URL validation
Risk Level: MediumVulnerable Code
javascript // Encode grid data as VerifiableURI const jsonString = JSON.stringify(gridData); const base64Data = Buffer.from(jsonString).toString('base64'); const verifiableUri = `data:application/json;base64,${base64Data}`;javascript if (args[0] === '--file') { // Load grid from JSON file const gridFile = args[1]; const gridData = JSON.parse(fs.readFileSync(gridFile, 'utf8')); updateGrid(gridData).catch(console.error); } else if (args[0] === '--example') {Technical Analysis
The script accepts arbitrary JSON from a user-selected file and immediately serializes it into an on-chain grid value. It does not validate the grid schema, required fields, item types, URL protocols, URL credentials, or origins.
The supported
iframeandexternalitem types contain active-content destinations in theirsrcandurlproperties. Consequently, a crafted grid file can contain phishing destinations, untrusted iframe origins, or non-HTTPS schemes. Althoughreferences/lsp28-spec.mdrecommends HTTPS and trusted sources, the executable script does not enforce those requirements.Whether a malicious scheme results in script execution depends on the security controls implemented by the downstream grid renderer. The confirmed issue in this project is that unsafe values can be signed and persisted without validation.
Attack Path
- An attacker creates or modifies a grid JSON file containing a malicious
external.urloriframe.src. - The attacker persuades an authorized operator to execute:
bash node scripts/update-grid.js --file malicious-grid.json - The script parses the file without schema or URL validation.
- The complete attacker-controlled object is b ...[truncated 831 chars]
- An attacker creates or modifies a grid JSON file containing a malicious
- Remediation
View remediation
Remediation Suggestions
-
Validate the entire input against a strict JSON schema before serialization:
- Require
isEditableto be a Boolean. - Require
itemsto be an array with a reasonable maximum length. - Permit only the documented
miniapp,iframe, andexternalitem types. - Enforce all required fields and reject unknown properties.
- Require unique, length-limited item IDs.
- Validate colors and optional size values.
- Require
-
Parse every
urlandsrcusing the standardURLclass and permit only HTTPS:javascript function validateHttpsUrl(value) { const parsed = new URL(value); if (parsed.protocol !== 'https:') { throw new Error('Only HTTPS URLs are permitted'); } if (parsed.username || parsed.password) { throw new Error('URLs containing credentials are not permitted'); } return parsed.toString(); } -
Consider enforcing an explicit origin allowlist for iframe sources. At minimum, reject loopback, link-local, and private-network destinations where relevant to consuming clients.
-
Display a normalized preview of all external and iframe destinations and require explicit operator confirmation before signing.
-
Downstream renderers must independently sanitize links, apply restrictive iframe sandbox attributes, and avoid relying exclusively on this producer-side validation.
-
