T09 · Insecure Skill Coding Practices
- Location
track-upvotes.js:22- Finding
Server-Side Request Forgery Through Insufficient Product Hunt URL Validation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but its URL handling can send requests to unintended hosts and its advertised Telegram alert feature is not implemented.
Install only if you are comfortable with a manual Node.js tool that makes outbound web requests. Use only known-good https://www.producthunt.com/posts/... URLs, and treat the Telegram alert claim as inaccurate unless the publisher updates the implementation. The publisher should add strict URL parsing, hostname allowlisting, redirect handling, and explicit network permission metadata before broad use.
track-upvotes.js:22Server-Side Request Forgery Through Insufficient Product Hunt URL Validation
The core tracking purpose mostly matches: the code does retrieve Product Hunt upvotes, comments, and rank, and it can compare current upvotes to the previous check. However, the description materially overstates behavior by promising Telegram alerts when rank improves. The code contains no Telegram integration, no outbound messaging, no scheduled trigger, and no alerting logic tied to leaderboard movement. Instead, it provides local fetch/scrape functions and a CLI for manual invocation, with ephemeral in-memory history only for the current process. So the declared description does not accurately represent the implemented capabilities.
The skill advertises functionality that reads public Product Hunt pages directly, which implies network access, but the manifest declares no explicit tool scope or permissions. This creates a transparency and policy gap: consumers or hosting platforms may approve the skill without understanding it can make outbound requests, weakening sandboxing and trust controls.
No suspicious patterns detected.