T09 · Insecure Skill Coding Practices
- Location
scripts/render_report.py:538- Finding
Stored HTML and JavaScript Injection in Generated Reports
- Content
View full analysis
str: if Template is None: raise RuntimeError("jinja2 not installed") tpl = Template(HTML_SKELETON) import json as _json tpl.globals["tojson"] = lambda v: _json.dumps(v, ensure_ascii=False) return tpl.render( lang=lang, generated_at=data.get("generated_at") or _dt.datetime.utcnow().strftime("%Y-%m-%d %H:%MZ"), overview=data.get("overview", {}), family_basic=data.get("family_basic", { "geo": [], "ipc": [], "legal": [], "legal_detail": [], "geo_analysis": "", "claim_comparison": [], }), litigated_patents=data.get("litigated_patents", []), cases=data.get("cases", []), inventors=data.get("inventors", []), conclusions=data.get("conclusions", { "geographic_risk": "", "geo_litigation_risk": [], "litigation_alert": "", "litigation_alert_summary": "", "trend_forecast": "", }), sources=data.get("sources", []), ) ``` Untrusted report fields are subsequently placed into HTML and JavaScript contexts: ```html{% if p.url %} {{ p.pn }} {% else %} {{ p.pn }} {% endif %}{{ p.title or "—" }}{% if p.abstract_image_url %}{% endif %} ``` ```html
Case {{ loop. ...[truncated 4338 chars]
- Remediation
View remediation
` with safe serialization, then parse the text content. 4. Validate every hyperlink and image URL before rendering: - Permit only `https`. - Reject credentials, control characters, protocol-relative URLs, and dangerous schemes such as `javascript:` and `data:` where not explicitly required. - Restrict patent links to documented PatSnap hosts. - Restrict image URLs to expected image-service hosts. - Add `rel="noopener noreferrer"` to links using `target="_blank"`. 5. Change `SKILL.md` so the direct HTML generation workflow explicitly requires contextual escaping and URL allowlisting. Prefer a single reviewed rendering implementation rather than agent-generated string concatenation. 6. Add a restrictive Content Security Policy, for example using a `` declaration suitable for standalone reports. Avoid inline event handlers so that `script-src` can disallow `unsafe-inline`. 7. Add regression tests containing hostile values in every output context, including: ```text ">javascript:alert(1) ``` The tests should verify that these values appear only as inert text or are rejected. ...[truncated 3 chars]
