T09 · Insecure Skill Coding Practices
- Location
scripts/generate_report.py:532- Finding
Stored HTML and URI-Scheme Injection in Generated Reports
- Content
View full analysis
- Remediation
View remediation
str: return html_utils.escape(str(value), quote=True) ``` 2. Parse metric fields into strict numeric types before formatting. Reject values that are not valid integers, decimals, or supported numeric suffixes instead of preserving arbitrary strings. 3. Validate profile URLs with `urllib.parse.urlparse` and enforce an explicit allowlist: ```python from urllib.parse import urlparse def safe_profile_url(value: str) -> str: parsed = urlparse(value) if ( parsed.scheme == "https" and parsed.hostname in {"www.xiaohongshu.com", "xiaohongshu.com"} and parsed.path.startswith("/user/profile/") ): return html_utils.escape(value, quote=True) return "#" ``` 4. Explicitly reject `javascript:`, `data:`, `file:`, and other non-HTTPS schemes. 5. Escape top-level values such as `category_label`, `date_str`, and `fetch_time` before inserting them into `HTML_TEMPLATE`. 6. Add a restrictive Content Security Policy. If inline JavaScript remains necessary, use a nonce or hash rather than broadly permitting inline execution. 7. Add regression tests containing HTML tags, quotes, event handlers, and unsafe URI schemes in every externally derived field. ]]>
