T09 · Insecure Skill Coding Practices
- Location
scripts/render_report.py:1571- Finding
Stored HTML and JavaScript Injection in Generated Reports
- Content
View full analysis
str: if s is None: return "" return str(s).replace("\r\n", "\n").replace("\r", "\n").strip() ``` The user-controlled requirement is incorporated directly into the generated Markdown: ```python def build_markdown_report(payload: Dict[str, Any]) -> str: """Build the exact Step 4 report body defined by SKILL.md/report-template.md.""" meta = _get(payload, "meta") or {} project_name = md_text(_get(meta, "project_name")) applicant = md_text(_get(meta, "applicant")) today_iso = md_text(_get(meta, "today_iso")) scope = md_text(_get(meta, "scope")) or "专利+论文+网络学术文献补充" requirement = md_text(_get(payload, "requirement_text")) or "未提及" analysis = _get(payload, "analysis") or {} summary = _get(payload, "summary") or {} issues = _list(payload, "issues") directions = _list(payload, "directions") units = _list(payload, "units") app = _get(payload, "appendix") or {} parts: List[str] = ["## 科研需求检索报告", ""] # ... parts.extend(["> **需求输入原文:**", ">", *["> " + line for line in requirement.split("\n")], ""]) ``` Raw HTML is then explicitly enabled during Markdown rendering: ```python def render_markdown_report(markdown_text: str) -> str: markdown_text = group_appendices_by_route(markdown_text) renderer = mistune.create_markdown(escape=False, plugins=["table"]) html_text = renderer(markdown_text) ``` A complete payload-provided Markdown document is also accepted as the preferred rendering source without sanitization: ```python def build_report_markdown(payload: Dict[str, Any]) -> str: payload = normalize_payload(payload) return md_text ...[truncated 3208 chars]- Remediation
View remediation
str: url = str(value or "").strip() parsed = urlparse(url) if parsed.scheme.lower() not in {"https", "http"}: return "" return url ``` 5. Add a restrictive Content Security Policy to the generated document as defense in depth. For a self-contained report with no scripts, an appropriate starting point is: ```html ``` Avoid allowing scripts unless they are essential. 6. Add regression tests that render malicious values through both `requirement_text` and `markdown_report`. Tests should verify that the generated HTML does not contain executable forms of: - `` - `` - `` - `[link](javascript:alert(1))` - Raw forms ...[truncated 258 chars]
