T09 · Insecure Skill Coding Practices
- Location
Skill.py:17- Finding
Server-Side Request Forgery Through Unrestricted Caller-Controlled URLs
- Content
View full analysis
Vulnerability Details
File Location:
Skill.py:17-35
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: HighVulnerable Code
python url = params.get("url") if not url: return self.fail("缺少 url 参数") method = params.get("method", "GET").upper() headers = params.get("headers", {}) url_params = params.get("params", {}) data = params.get("data", {}) timeout = params.get("timeout", 10) default_headers = { "User-Agent": "ClawHub-Skill/1.0", "Content-Type": "application/json" } headers = {**default_headers, **headers} if method == "GET": resp = requests.get(url, headers=headers, params=url_params, timeout=timeout) elif method == "POST": resp = requests.post(url, headers=headers, params=url_params, json=data, timeout=timeout) else: return self.fail(f"不支持的请求方法:{method}")Technical Analysis
The
run()method passes a caller-controlled URL directly torequests.get()orrequests.post()without validating the URL scheme, hostname, port, resolved IP address, or redirect destinations. Consequently, an untrusted caller can direct the host running this skill to connect to loopback interfaces, private networks, link-local services, cloud metadata endpoints, or arbitrary Internet hosts.The caller can also control request headers, query parameters, and POST data, making the skill a flexible HTTP relay rather than a narrowly scoped API documentation assistant. The implementation does not disable redirects, so a public URL may redirect the request to a prohibited internal destination unless every redirect hop is separately validated.
After the request completes, JSON responses are returned without an explicit size limit. Non-JSON response bodies are returned up to 1,000 characters. This response disclosure allows an attacker to retrieve information from reachable internal services rather than merely performing blind network probes.
This beh ...[truncated 1828 chars]
- Remediation
View remediation
Remediation Suggestions
- If outbound HTTP access is unnecessary for the documented API-writing purpose, remove this functionality entirely.
- Otherwise, permit only explicitly approved HTTPS hostnames and ports through a strict allowlist.
- Parse URLs with a standards-compliant URL parser and reject unsupported schemes, embedded credentials, malformed hosts, unexpected ports, and ambiguous address representations.
- Resolve destination hostnames before connecting and reject loopback, private, link-local, reserved, multicast, unspecified, and other non-public IP ranges for both IPv4 and IPv6.
- Protect against DNS rebinding by ensuring the validated address is the address actually used for the connection.
- Disable redirects by default. If redirects are required, repeat complete scheme, hostname, port, and resolved-address validation for every redirect hop.
- Restrict caller-controlled headers to a minimal allowlist. Explicitly block sensitive or routing-relevant headers where they are not required.
- Apply request and response size limits, including limits before JSON parsing, to reduce data exposure and resource exhaustion risks.
- Use fixed, bounded timeout values rather than accepting arbitrary caller-supplied timeout settings.
- Enforce network-level egress controls that prevent the process from accessing metadata services and internal administrative networks.
- Log rejected destinations and anomalous request attempts without recording credentials or other sensitive header values.
