T09 · Insecure Skill Coding Practices
- Location
scripts/sota_public_safety.py:307- Finding
Incomplete Secret Redaction and Markdown Injection in Generated Audit Summaries
- Content
View full analysis
str: value = value.strip() if not value: return "" if "://" in value: return sanitize_url_for_display(value, allow_raw=allow_raw) if is_absolute_like(value): return sanitize_path(value, allow_absolute_paths=allow_raw) return value ``` Both summary renderers recursively process string values without retaining the associated field name. They then place the resulting content directly into Markdown: ```python def sanitize_value(value: Any) -> Any: if isinstance(value, str): return sanitize_ref(value) if isinstance(value, list): cleaned = [] for item in value: sanitized = sanitize_value(item) if sanitized in ("", [], {}): continue cleaned.append(sanitized) return cleaned if isinstance(value, dict): cleaned = {} for key, item in value.items(): sanitized = sanitize_value(item) if sanitized in ("", [], {}): continue cleaned[key] = sanitized return cleaned return value def add_field(lines: list[str], label: str, value: Any) -> None: value = sanitize_value(value) if value in (None, "", [], {}): return rendered = json.dumps(value, ensure_ascii=True, sort_keys=True) if isinstance(value, (list, dict)) else str(value) lines.append(f"- {label}: `{rendered}`") ``` The generated content is written as a supposedly sanit ...[truncated 3155 chars]- Remediation
View remediation
