T09 · Insecure Skill Coding Practices
- Location
scripts/patch_color.py:89- Finding
Unvalidated color arguments allow JavaScript source injection into Claude Code
- Content
View full analysis
- Remediation
View remediation
str: parts = value.split(",") if len(parts) != 3: raise ValueError("RGB must contain exactly three components") values = [int(part, 10) for part in parts] if any(value < 0 or value > 255 for value in values): raise ValueError("RGB components must be between 0 and 255") return f"rgb({values[0]},{values[1]},{values[2]})" ``` 2. Restrict ANSI values to an explicit allowlist of supported color identifiers. For example: ```python ALLOWED_ANSI = { "ansi:black", "ansi:red", "ansi:green", "ansi:yellow", "ansi:blue", "ansi:magenta", "ansi:cyan", "ansi:white", "ansi:blackBright", "ansi:redBright", "ansi:greenBright", "ansi:yellowBright", "ansi:blueBright", "ansi:magentaBright", "ansi:cyanBright", "ansi:whiteBright", } ``` 3. Reject quotation marks, backslashes, control characters, line breaks, and every value outside the expected grammar. 4. Use safe serialization when generating JavaScript string literals instead of direct interpolation. 5. Verify that each replacement produces the exact expected syntax and occurrence count before writing the result. 6. Write to a temporary file, validate the generated bundle, and atomically replace the original only after validation succeeds. ]]>
