T09 · Insecure Skill Coding Practices
- Location
scripts/report_generator.py:531- Finding
Stored HTML and JavaScript Injection in Generated Review Reports
- Content
View full analysis
Generated: {self.generated_at[:19]} {f' | Branch: {meta.get("branch", "N/A")}' if meta.get("branch") else ''} {f' | Range: {meta.get("base_sha", "")[:8]}..{meta.get("head_sha", "")[:8]}' if meta.get("base_sha") else ''} | Reviewer: {meta.get("reviewer", "agent")} ``` ```python items.append(f"""{f['path']} {ann_badge} +{f['additions']} -{f['deletions']}""") ``` ```python annotations_html += f"""""" ``` ```python @staticmethod def _safe_id(path: str) -> str: """Convert file path to safe HTML ID.""" return path.replace("/", "-").replace(".", "-").replace(" ", "-") ``` ### Technical Analysis The report generator embeds several dynamic values directly into HTML without context-appropriate escaping: - Repository-controlled file paths are inserted into element text and the quoted `data-target` attribute. - Annotation reviewer names are inserted directly into ...[truncated 2315 chars]{sev} L{ann['line']} {ann.get('reviewer', '')}{self._escape(ann['message'])}{suggestion_html}- Remediation
View remediation
``` For a fully self-contained report, move the inline script to a separately trusted resource or use a nonce/hash-based CSP. 5. Add regression tests using malicious values containing: ```text ">" onclick="alert(1) ``` The tests should verify that these strings appear only as encoded text and cannot create elements or attributes. ]]>
