T09 · Insecure Skill Coding Practices
- Location
scripts/md2html.py:812- Finding
Untrusted Markdown Can Inject Executable HTML and JavaScript
- Content
View full analysis
{content_html}``` Mermaid is also explicitly configured with a permissive security level: ```javascript mermaid.initialize({ startOnLoad: false, theme: 'default', securityLevel: 'loose', suppressErrorRendering: true }); ``` ### Technical Analysis Python-Markdown preserves raw HTML by default. The converter does not sanitize the output of `md.convert()` before interpolating it into the final document. Consequently, raw elements and attributes supplied through the Markdown input can become active browser content. Potential payload classes include: - `- Remediation
View remediation
