T09 · Insecure Skill Coding Practices
- Location
SKILL.md:307- Finding
Unescaped User-Controlled Values in Generated HTML Reports
- Content
View full analysis
技术名称:{{技术名称}} ``` ```markdown - `{{技术名称}}`: Extracted from the technical solution title or invention name supplied by the user. ``` ```html{{评价说明文字}}``` ```markdown | `{{评价说明文字}}` | Overall assessment sentence, numbered primary risks, and recommended action | ``` ### Technical Analysis The Skill directs the agent to extract a title from user-provided patent materials and interpolate it into an HTML report through the `{{技术名称}}` placeholder. It also inserts generated assessment content through `{{评价说明文字}}`. No requirement is provided to HTML-escape, sanitize, or validate these dynamic values before interpolation. If an attacker controls a patent title, technical disclosure, or other report source, the attacker could supply HTML such as an image with an event handler, an iframe, a deceptive hyperlink, or a script-capable SVG element. Raw interpolation would cause the browser or report viewer to interpret that content as markup rather than plain text. Exploitability depends on the report generator performing literal placeholder substitution and the report viewer allowing active HTML. The Skill does not require either contextual output encoding or a restrictive Content Security Policy, so it does not establish a safe rendering boundary. ### Attack Path 1. An attacker prepares a patent title or technical disclosure containing malicious HTML. 2. A user submits that document or title for pre-filing assessment. 3. The Skill extracts the attacker-controlled value as the technical name or incorporates it into assessment text. 4. The report generator substitutes the value directly into ...[truncated 851 chars]- Remediation
View remediation
