T09 · Insecure Skill Coding Practices
- Location
SKILL.md:68- Finding
Unescaped External Data Is Interpolated into Executable HTML Reports
- Content
View full analysis
高质量技术人才科创能力画像报告{{inventor}}{{assignee}}📅报告日期:{{report_date}}🌐技术领域:{{tech_domain}}``` ```html 1 CN... 专利标题 YYYY-MM-DD IPC分类 有效 X次 ``` ### Technical Analysis The Skill requires user-controlled values, including the inventor and institution names, and externally retrieved patent metadata to be inserted into a self-contained HTML report. It does not require HTML entity encoding, context-sensitive output escaping, URL validation, or sanitization. If an input or external metadata field contains HTML syntax, the browser can interpret that value as active markup rather than plain text. Event-handler attributes, dangerous URL schemes, SVG content, or other executable HTML constructs could consequently run JavaScript when a generated report is opened. The patent link also uses `target="_blank"` without requiring `rel="noopener noreferrer"`. Depending on browser behavior, the opened page may receive access to `window.opener` and attempt to manipulate the original report page. ### Attack Path 1. An attacker supplies a cra ...[truncated 1436 chars]- Remediation
View remediation
`, `"`, and `'`. - HTML attributes: use attribute-specific encoding and quoted attributes. - URLs: construct them from validated components and percent-encode the patent identifier. 2. Treat all user input and all MCP-returned metadata as untrusted, including names, organizations, patent titles, IPC values, legal status, technology domains, and patent identifiers. 3. Prohibit insertion through raw HTML operations such as `innerHTML`. When JavaScript rendering is necessary, use `textContent` and DOM element creation. 4. Validate patent identifiers with a strict allowlist before including them in URLs. Reject control characters, markup, unexpected schemes, and path or query delimiters that are not part of the identifier format. 5. Add `rel="noopener noreferrer"` to every link using `target="_blank"`. 6. Add a restrictive Content Security Policy, preferably through an HTTP header or an equivalent report-delivery control. If a meta policy is required for standalone HTML, disallow external scripts and object embedding. 7. Avoid inline event handlers where possible. The fixed back-to-top action should use a locally registered event listener. 8. Add automated tests using payloads in every dynamic field, including closing tags, event handlers, SVG payloads, encoded markup, quotes, and dangerous URL schemes. ]]>
