T09 · Insecure Skill Coding Practices
- Location
scripts/douyin_weekly_surge.py:163- Finding
Untrusted API Response Fields Rendered as Active Markdown
- Content
View full analysis
Vulnerability Details
File Location:
scripts/douyin_weekly_surge.py:163-182
Vulnerability Type: Markdown output injection and unsafe URL rendering
Risk Level: MediumVulnerable Code
python for idx, item in enumerate(items[:limit], start=1): raw_title = (item.get("aweme_desc") or "-").replace("|", "|").replace("[", "【").replace("]", "】").replace("\n", " ").replace("\r", " ") work_url = item.get("share_url", "") if work_url: title = f"[{raw_title}]({work_url})" else: title = raw_title author = item.get("user_nickname", "-") cat = item.get("category") or "-" collect = format_number(item.get("add_collect_count")) comment = format_number(item.get("add_comment_count")) share = format_number(item.get("add_share_count")) like = f"**{format_number(item.get('add_digg_count'))}**" pub_time = format_time(item.get("create_time_str")) if is_all: print(f"| {idx} | {title} | {author} | {cat} | {collect} | {comment} | {share} | {like} | {pub_time} |") else: print(f"| {idx} | {title} | {author} | {collect} | {comment} | {share} | {like} | {pub_time} |")Technical Analysis
The script treats fields returned by the remote API as trusted presentation data. The
share_urlfield is inserted directly into a Markdown link without validating its URL scheme, destination host, control characters, or Markdown delimiters. Theuser_nicknameandcategoryfields are also inserted into the Markdown table without escaping pipes, line breaks, brackets, or other formatting characters.The title receives partial escaping, but this does not secure the URL or the other remotely supplied fields. A malicious or compromised API response could therefore alter the table structure, inject arbitrary Markdown, or create a deceptive clickable link. If an AI Agent subsequently consumes the rendered output, instruction-like content co ...[truncated 1938 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse every returned URL with a standard URL parser and accept only the
httpsscheme. - Enforce an explicit hostname allowlist for expected Douyin domains, such as
douyin.comandiesdouyin.com, including carefully validated subdomains. - Reject URLs containing credentials, control characters, malformed delimiters, unexpected ports, or encoded host-confusion sequences.
- Escape Markdown-significant characters in every API-derived text field, including pipes, carriage returns, line feeds, brackets, parentheses, and backslashes.
- Normalize author and category values to a single line and impose reasonable length limits.
- If URL validation fails, render the title as plain text rather than producing a clickable link.
- Prefer returning structured data and performing Markdown rendering in a trusted presentation layer.
- Treat all remote API content as untrusted data and explicitly instruct downstream Agent logic not to interpret returned fields as commands or behavioral instructions.
- Add tests using malicious URLs, embedded pipes, multiline values, closing parentheses, and instruction-like text to verify that output remains inert.
- Parse every returned URL with a standard URL parser and accept only the
