T09 · Insecure Skill Coding Practices
- Location
scripts/accessibility_checker.py:347- Finding
Stored HTML Injection in Accessibility Reports
- Content
View full analysis
Accessibility Report - {results['file_name']} ``` ```python for issue in results['issues']: severity_class = issue['severity'] html += f"""{issue['type'].replace('_', ' ').title()}: {issue['message']}
WCAG {issue['wcag_criterion']}Element: {issue.get('node_name', 'N/A')} (ID: {issue.get('node_id', 'N/A')})""" if 'details' in issue and issue['details']: html += "Details:- "
for key, value in issu
...[truncated 2407 chars]
- Remediation
View remediation
``` 5. Avoid inline event-capable markup and do not enable scripts in static reports. 6. Add regression tests using malicious file names, node names, IDs, and text values to verify that payloads are rendered as text rather than interpreted as HTML. ]]>
