T09 · Insecure Skill Coding Practices
- Location
assets/paw-app.js:191- Finding
Stored Cross-Site Scripting Can Expose the OpenClaw Gateway Token
- Content
View full analysis
`; }; renderer.link = function(token) { const href = token.href || ''; const text = token.text || href; return `${text}`; }; marked.setOptions({ renderer }); function renderMarkdown(text) { try { if (typeof marked !== 'undefined') { return marked.parse(text); } return escHtml(text).replace(/\n/g, '
'); } catch (e) { console.warn('[renderMarkdown error]', e); return escHtml(text).replace(/\n/g, '
'); } } ``` ```javascript if (role === 'assistant' || role === 'system') el.innerHTML = renderMarkdown(text); ``` ```javascript if (textStr) { const d = document.createElement('div'); d.innerHTML = renderMarkdown(textStr); wrapper.appendChild(d); } ``` ### Technical Analysis Assistant and system messages originate from a remote Gateway or agent and must be treated as untrusted content. The application passes this content to `marked.parse()` and assigns the resulting HTML directly to `innerHTML` without applying an HTML sanitizer. Raw HTML accepted by the Markdown parser can therefore introduce executable elements or event-handler attributes. The custom link and image renderers also interpolate `href` values d ...[truncated 1774 chars]- Remediation
View remediation
