T09 · Insecure Skill Coding Practices
- Location
scripts/visualize.py:58- Finding
Stored Script Injection in Generated Knowledge Graph HTML
- Content
View full analysis
- Remediation
View remediation
``` 3. Serialize the data with HTML-safe escaping, at minimum replacing `<`, `>`, `&`, U+2028, and U+2029 with Unicode escapes. For example: ```python data_json = json.dumps(data, ensure_ascii=False) data_json = ( data_json.replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` 4. Parse the inert data explicitly: ```javascript const DATA = JSON.parse( document.getElementById('graph-data').textContent ); ``` 5. Replace the tag `innerHTML` assignment with DOM construction using `textContent`: ```javascript const tagsElement = document.getElementById('ttTags'); tagsElement.replaceChildren(); for (const tag of d.tags) { const span = document.createElement('span'); span.className = 'tt-tag'; span.textContent = tag; tagsElement.appendChild(span); } ``` 6. Add a restrictive Content Security Policy that disallows inline scripts and limits outbound connections. 7. Add regression tests using values containing ``, HTML event handlers, quotes, backslashes, and Unicode line separators. 8. Replace the bundled sample data with a clearly defined, consistently handled data placeholder. ]]>
