T09 · Insecure Skill Coding Practices
- Location
scripts/ai-act-check.py:408- Finding
Unescaped Remote Content in Generated HTML Reports
- Content
View full analysis
{current_cat}\n' icon = "✅" if r.get("passed") else "❌" cls = "pass" if r.get("passed") else "fail" sev = r.get("severity") or "" sev_badge = "" if sev: color = sev_cls.get(sev, "#64748b") sev_badge = f'{sev_label.get(sev, sev)}' rec = r.get("recommendation") or "Keep it up" meta = r.get("meta") or {} rt = meta.get("remediation_template") if not r.get("passed") and rt: rec = f"🔧 {rt.get('summary', '')}(整改期限约 {rt.get('deadline_days', '')} 天)" case_html = "" case_keys = (r.get("meta") or {}).get("related_case_keys") or [] if case_keys and cases_by_ref: shown = 0 li = [] for ck in case_keys: for line in cases_by_ref.get(ck, []): li.append(f"- {line}
") shown += 1 if shown >= 3: break if shown >= 3: break if li: case_html = f'📚 关联执法案例' rows += f"""{icon}{r.get('name')}{r.get('legal_ref') or ''}{sev_badge}{cls.upper()}{rec}{case_html}\n""" ``` The generated report is subsequently written to a user-selected file: ```python if args.output: with open(args.output, "w", encoding="utf-8") as f: f.write(report) ``` ### Technical Analysis The HTML renderer inserts values obtained from clou ...[truncated 2807 chars]- {"".join(li)}
- Remediation
View remediation
``` Output encoding remains required because a CSP does not prevent all markup injection or report manipulation. 6. Add regression tests covering all remotely sourced fields with payloads such as: ```html</td><form>...</form> ``` Tests should verify that these strings appear only as encoded text and cannot create DOM elements or executable handlers. 7. Consider generating the report through a template system with automatic HTML escaping rather than manually concatenating HTML strings. ]]>
