T09 · Insecure Skill Coding Practices
- Location
scripts/ai-persona-check.py:385- Finding
Unescaped Cloud-Controlled Data in Generated HTML Report
- Content
View full analysis
= 80 else "#ff9800" if score >= 60 else "#f44336" rows = "" current_cat = "" for r in items: if r.get("category_name") != current_cat: current_cat = r.get("category_name", "") rows += f'{current_cat}\n' icon = "✅" if r.get("passed") else "❌" cls = "pass" if r.get("passed") else "fail" rec = r.get("recommendation") or "继续保持" rows += f"""{icon}{r.get('name')}{r.get('legal_ref') or ''}{cls.upper()}{rec}\n""" ``` ### Technical Analysis The HTML renderer directly interpolates report values into HTML without context-appropriate escaping. The affected values include: - `category_name` - `name` - `legal_ref` - `recommendation` During cloud-scored operation, these fields may originate from responses returned by `compliancehub.cn`. They therefore cross a remote trust boundary before being inserted into a locally generated HTML document. An attacker who compromises the cloud service, its rule data, or the response delivery path could place HTML markup or executable browser content in these fields. Because the generated document has no escaping or restrictive Content Security Policy, the browser will interpret injected markup when the user opens the report. The pinned HTTPS endpoint reduces redirection and network interception risks, but it does not protect against malicious or compromised upstream data. ### Attack Path 1. The user starts a scored assessment and requests HTML output, such as: ```bash python3 scripts/ai-persona-check.py --format ...[truncated 1350 chars]- Remediation
View remediation
' f'{category}' f'\n' ) rows += ( f'{icon}{name}' f'{legal_ref}{cls.upper()}' f'{recommendation}\n' ) ``` 2. Prefer a maintained template engine with automatic HTML escaping if third-party dependencies are acceptable. 3. Validate cloud response schemas and reject values with unexpected types or excessive lengths. Validation should supplement, not replace, output escaping. 4. Add a restrictive Content Security Policy to generated reports, for example: ```html ``` 5. Add regression tests using payloads such as ``, ``, quotes, and malformed tags. Verify that the generated document contains escaped text and no executable elements or event-handler attributes. ]]>
