T09 · Insecure Skill Coding Practices
- Location
SKILL.md:156- Finding
Private-Network Access Override Creates an SSRF Primitive
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:156; supporting schema atschema.md:58-63
Vulnerability Type: Server-Side Request Forgery through configurable private-network access
Risk Level: HighVulnerable code snippet:
markdown - Requests to private or loopback IP addresses are blocked by default. Set `allow_private` to `true` to override.json "allow_private": { "default": false, "description": "Set to true to allow requests to private or loopback IP addresses.", "required": false, "type": "boolean" }Technical Analysis
The Skill is a general-purpose HTTP client and therefore legitimately requires outbound network access. However, ordinary webhook and third-party REST API operations do not require access to private, loopback, link-local, or cloud metadata addresses.
The
allow_privateoption lets an Agent disable the principal SSRF boundary using an ordinary request parameter. The schema does not require user approval, administrative authorization, or an allowlisted destination before enabling this behavior. The reviewed instructions also do not specify protections against DNS rebinding, alternate IP encodings, link-local destinations, cloud metadata services, or redirects from public URLs to private addresses.Because the tool returns the response body and metadata to the Agent, private-network access can potentially be used for both reconnaissance and data retrieval.
Attack Path
- An attacker supplies a prompt, document, API response, or other content that influences the Agent.
- The content instructs the Agent to request an attacker-selected private, loopback, link-local, or metadata URL.
- The Agent invokes the request action with
allow_private: true. - The hosted request service connects to a destination that is inaccessible to the external attacker.
- The service returns the status, headers, final URL, and response body to the Agent.
...[truncated 721 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
allow_privatefrom the general request schema. - If private access is an essential enterprise feature, place it behind an administrator-controlled policy rather than an Agent-controlled boolean.
- Require explicit, per-request user approval that displays the resolved destination and explains the risk.
- Use destination allowlists scoped to the specific integration.
- Block loopback, private, link-local, multicast, reserved, and cloud metadata ranges for both IPv4 and IPv6.
- Resolve and validate every destination immediately before connection.
- Revalidate every redirect target and prohibit redirects from public to non-public addresses.
- Pin validated DNS results through connection establishment to mitigate DNS rebinding.
- Normalize and reject alternative IP address representations.
- Record security events without logging credentials or sensitive response bodies.
- Remove
