T09 · Insecure Skill Coding Practices
- Location
src/utils/utils.js:23- Finding
Terminal Escape-Sequence Injection Through Unsanitized CLI Input
- Content
View full analysis
"'&]/.test(keyword)) { utils.printError( `搜索关键词包含特殊字符 < > " ' &, 请输入普通关键词, 例如: 新媒体`, ); return false; } ``` ### Technical Analysis ANSI-compatible terminals interpret control sequences beginning with the ESC byte (`0x1B`) instead of displaying those bytes as ordinary text. The shared `printLog` function converts untrusted values to strings but does not remove, encode, or visibly escape control characters before writing them to stderr. The affected CLI commands log raw user input before URL or keyword validation can make it safe for terminal presentation. The keyword validator rejects selected characters s ...[truncated 2238 chars]- Remediation
View remediation
