T09 · Insecure Skill Coding Practices
- Location
SKILL.md:260- Finding
Stored HTML and JavaScript Injection in Generated Reports
- Content
View full analysis
{i+1}{c["name"]}{c.get("module","-")}{c.get("error_type","-")}{c.get("error_message","-")}{c.get("severity","-")}' for i, c in enumerate(data.get('failed_cases', [])))} ``` ```python {''.join(f'{i+1}{c["name"]}{c["time"]:.2f}{"✅" if c["status"]=="passed" else "❌"}' for i, c in enumerate(data.get('slowest_cases', [])[:10]))} ``` ```python {''.join(f'{p["pattern"]}{p["count"]}{p["percentage"]:.1f}%{p["suggestion"]}' for p in data.get('failure_patterns', []))} ``` ```python {''.join(f'- {s}
' for s in data.get('suggestions', []))} ``` ```python{data.get('release_verdict','待定')}
{data.get('release_note','')}
``` ### Technical Analysis The HTML report generator directly interpolates test names, module names, error messages, failure-pattern descriptions, suggestions, and release information into HTML markup. No HTML escaping, contextual output encoding, sanitization, or validation is applied. Test reports and log-derived values must be considered untrusted because they may contain attacker-controlled test names, assertion messages, parameter values, service responses, or exception text. A value such as: ```html``` would be inserted into the generated report as active markup rather than displayed as text. The `release_color` value is also placed into a CSS declaration without validation. Although this sink is less directly exploitable in modern browsers than raw HTML insertion, it violates contextual encoding requirements and ...[truncated 1687 chars]
- Remediation
View remediation
"> ``` The generated report must display these values as inert text. ]]>
