T09 · Insecure Skill Coding Practices
- Location
SKILL.md:540- Finding
Unrestricted URL Fetching Enables SSRF and External Disclosure of Retrieved Content
- Content
View full analysis
= 0.02): Clean HTML, send text to Gemini 2.5 Flash (JSON mode) 5. **JS-rendered** (density < 0.02, e.g. Wix, Framer): Screenshot with Playwright, send to Gemini Vision 6. **Screenshot height cap**: If screenshot > 6000px tall, resize proportionally to fit 7. **Large menus** (>12k chars text): Chunked extraction, merge like PDF multi-page. ``` ### Technical Analysis The Skill instructs generated code to fetch a user-supplied restaurant URL using `requests`, with Playwright as a fallback for pages classified as JavaScript-rendered. It does not require validation of the URL scheme, resolved IP address, redirects, destination port, or final response URL. Consequently, an attacker may supply a URL targeting a resource accessible from the execution environment but not from the public Internet. Potential targets include: - Loopback services such as `127.0.0.1` or `::1` - Private network services - Link-local resources and cloud instance metadata - Services reached through DNS rebinding - Public URLs that redirect to prohibited internal destinations The fetched response is then cleaned and sent to Gemini as text, or rendered and sent as a screenshot. This creates an SSRF-to-disclosure chain: content retrieved from an internal destination may be transmitted to an external API. Fetching restaurant pages is necessary for the declared functionality, but unrestricted network access exceeds minimum privilege. Access should be constra ...[truncated 1318 chars]- Remediation
View remediation
