T09 · Insecure Skill Coding Practices
- Location
assets/mindmap/render_mindmap.py:96- Finding
Stored HTML and JavaScript Injection in Mind-Map Reports
- Content
View full analysis
` value is escaped. ### Vulnerable Code ```python def render(d): # Column 1: product p = d["product"] col_product = _node("product", f'{p["name"]}
{p.get("desc","")}') # Column 2: systems (accent: red default / gold horizontal) sys_nodes = [] for s in d.get("systems", []): gold = s.get("accent") == "gold" style = ' style="border-left-color:var(--gold)"' if gold else '' idstyle = ' style="color:var(--gold)"' if gold else '' sys_nodes.append( f'') # Column 3: subsystems (plain labels) sub_nodes = [_node("subsys", s) for s in d.get("subsystems", [])] # Column 4: components (merge => component is also key part) comp_nodes = [] for c in d.get("components", []): cls = "component merge" if c.get("merge") else "component" inner = f'{s["id"]}' f'{s["name"]}{s.get("tag","")}{c["id"]}{c["name"]}' if c.get("tag"): inner += f'{c["tag"]}' comp_nodes.append(_node(cls, inner)) # Column 5: parts (star / muted reference rows) part_nodes = [] for pt in d.get("parts", []): if pt.get("muted"): inner = (f'{pt["id"]}' f'{pt["name"]}') part_nodes.append(f'- Remediation
View remediation
` and `
`. Remove: - `link ``` 6. **Treat external and model-generated content as untrusted** Validate and sanitize text obtained from users, Web searches, patents, papers, MCP results, and delegated agents before rendering i ...[truncated 18 chars]
