T09 · Insecure Skill Coding Practices
- Location
SKILL.md:214- Finding
DOM-Based Cross-Site Scripting Through Unsanitized Store and Directions Data
- Content
View full analysis
${store.properties.address}${store.properties.phone || ''}
`; ``` The popup implementation also interpolates untrusted properties into `setHTML()`: ```javascript new mapboxgl.Popup({ closeOnClick: true }) .setLngLat(store.geometry.coordinates) .setHTML( `${store.properties.name}
${store.properties.address}
${store.properties.phone}
${store.properties.website ? `Visit Website` : ''}` ) .addTo(map); ``` The directions reference uses the same unsafe pattern for store properties: ```javascript const popup = new mapboxgl.Popup({ closeOnClick: true }) .setLngLat(store.geometry.coordinates) .setHTML( `${store.properties.name}
${store.properties.address}
${store.properties.phone}
${userLocation ? 'Get Directions' : ''}` ) .addTo(map); ``` Directions API response fields are also converted into HTML without escaping: ```javascript popup.setHTML( `${store.properties.name}
${directions.distance} mi • ${directions.duration} min
${store.properties.address}
- Remediation
View remediation
{ getDirections(store.properties.id); }); ``` 4. **Validate external links.** Parse website values and allow only approved protocols: ```javascript function getSafeWebsite(value) { try { const url = new URL(value); return url.protocol === 'https:' ? url.href : null; } catch { return null; } } ``` Create links throu ...[truncated 1103 chars]
