Security checks for vulnerabilities and agentic risk
Overview
The Java review skill is mostly coherent, but its optional HTML report template lacks a clear escaping boundary for reviewed code and document content.
Review or modify the HTML reporting path before using it on untrusted code or documents. Markdown output is lower risk, but HTML reports should escape source snippets, filenames, issue text, and consistency-check content before opening or hosting them.
Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)
T09 · Insecure Skill Coding Practices
Warning
Location
assets/report-template.html:139
Finding
Unescaped Review Content Can Cause HTML Injection in Generated Reports
Content
View full analysis
🔍 问题详情
{issues_html}
{consistency_section}
```
The related report requirements in `SKILL.md:76-96` require reviewed source code to be included in generated reports and permit HTML output:
```markdown
- **默认输出**:Markdown
- **可选输出**:HTML(用户指定时)
```markdown
输出格式: HTML
```
### 报告结构
1. 概述(审查文件数、问题统计)
2. 问题列表(按 Critical → Major → Minor → Suggestion 排序)
3. 修复建议(含代码对比)
4. 一致性检查(如果提供了需求/设计文档)
### 修复建议格式(必须包含)
**每个问题必须包含以下结构:**
```
### N. [严重程度] 问题标题
文件:`文件名:行号`
**问题描述**:
[简短描述问题]
**问题代码**:
```java
// 完整的修复前代码片段(至少 3 行上下文)
```
```
### Technical Analysis
The Skill accepts untrusted Java source files, Git diffs, and optional design documents. It instructs the Agent to reproduce source excerpts and findings in a report and supports HTML as an output format.
The HTML template places `{issues_html}` and `{consistency_section}` directly into the document body. No instruction requires HTML encoding, allowlist sanitization, or creation of code blocks through text-only DOM operations. Consequently, source text, filenames, comments, strings, issue descriptions, or design-document content containing HTML metacharacters may be interpreted as markup rather than displayed as literal text.
For example, malicious reviewed content containing the following sequence could escape an intended code element if inserted without encoding:
```html
```
The vulnerability depends on the report generator interpolating these placeholders without escaping, which is the unsafe behavior implied by the current template contract. Alth
...[truncated 1601 chars]
Remediation
View remediation
`, `"`, and `'` before placing untrusted text into HTML.
3. Render source excerpts only as escaped text inside `text
` elements. Do not treat reviewed source text as preformatted HTML.
4. Build issue markup from trusted fixed templates while inserting untrusted values through text-node APIs or an auto-escaping template engine.
5. If limited formatting must be accepted, sanitize it with a maintained strict allowlist that rejects scripts, event-handler attributes, dangerous URLs, embedded frames, and active SVG or MathML content.
6. Add a restrictive Content Security Policy, such as:
```html
```
7. Document the escaping requirement in `SKILL.md` so an Agent cannot reasonably interpret `{issues_html}` as permission to copy raw source text into markup.
8. Add regression tests using payloads such as:
```text
">
```
The tests should verify that these values appear only as literal text and never create executable DOM elements.
]]>
The natural-language instructions, examples, and usage guidance are all presented in Chinese, which effectively forces a specific language for users of the skill. Under the policy, locale or language constraints should either be optional for the user or explicitly justified as region-specific.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
The HTML template explicitly sets the document language to zh-CN, and the visible report content is also fixed in Chinese. This appears to impose a specific language/locale without user opt-in or any documented justification that the skill is intended only for a China-specific context.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding
This markdown template hard-codes Chinese headings and labels throughout the entire report, such as the title and section names, with no indication that the user can choose another language. The policy specifically flags language or locale constraints when they are imposed without user opt-in or clear justification.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding
This markdown file contains natural-language instructions exclusively in Chinese, starting with the title and continuing throughout the full document. Under the policy rule for language or locale constraints, forcing a single language without user opt-in or justification is a natural-language policy violation.