Back to skill

Security audit

PrestaShop Bridge V1

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent PrestaShop bridge contract, but it needs review because it defines high-impact store write operations and an under-scoped server-side image download field while its security verification package is incomplete.

Review this before installing in a production store. Require the publisher to add the missing .env.bridge.example and examples.http files, clearly mark any HMAC fixture as test-only, and constrain image downloads to approved HTTPS asset hosts with private-network, redirect, DNS rebinding, timeout, and size protections. Treat bridge:write credentials as authority to mutate business data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
schemas/product-import-request.schema.json:58
Finding

Unrestricted Remote Image URLs Enable Server-Side Request Forgery

Content
View full analysis

Vulnerability Details

File Location: schemas/product-import-request.schema.json, lines 58–64
Related API Location: openapi.yaml, lines 300–318
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: High

Vulnerable Code

json
"images_to_download": {
  "type": "array",
  "items": {
    "type": "string",
    "format": "uri"
  }
}

The corresponding product-import endpoint accepts this field:

yaml
/v1/jobs/products/import:
  post:
    summary: Create a product import job
    requestBody:
      required: true
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ProductImportRequest'
          examples:
            default:
              value: {"batch_id": "batch-2026-03-21-01", "items": [{"reference": "NEW-001", "name": {"fr": "Nouveau", "en": "New"}, "price_ht": 10.0, "stock_quantity": 100, "images_to_download": ["https://assets.example.com/img/new-001.jpg"]}], "options": {"create_if_missing": true, "update_if_exists": true, "skip_images_errors": false}}

Technical Analysis

The product-import contract permits authenticated clients to supply arbitrary URI values that the asynchronous Bridge worker is expected to download. The schema validates only that each value has the generic uri format. It does not restrict the scheme to HTTPS, constrain destination hosts, reject non-public IP address ranges, or specify redirect revalidation.

No compensating SSRF controls were identified in the reviewed security and trust documentation. In particular, the contract does not require:

  • An allowlist of trusted image hosts
  • Rejection of loopback, private, link-local, multicast, or reserved addresses
  • Blocking cloud instance-metadata endpoints
  • DNS resolution and rebinding protection
  • Revalidation of every redirect destination
  • Response-size, redirect-count, or download-time limits

Consequently, a user holding the documented bridge:write permission may be able to c ...[truncated 1983 chars]

Remediation
View remediation

Remediation Suggestions

  1. Restrict accepted schemes

    • Permit https only.
    • Explicitly reject file, ftp, gopher, data, and other unsupported schemes.
    • Enforce the restriction in runtime code rather than relying exclusively on JSON Schema.
  2. Use a destination allowlist

    • Restrict downloads to explicitly approved image hosts or controlled asset domains.
    • If arbitrary public hosts are a business requirement, apply strict network-address validation.
  3. Block non-public destinations

    • Resolve the hostname before connecting.
    • Reject loopback, private, link-local, multicast, unspecified, reserved, and documentation address ranges for both IPv4 and IPv6.
    • Explicitly block known cloud metadata destinations.
    • Connect only to the validated resolved address while preserving correct TLS hostname verification.
  4. Prevent DNS rebinding and redirect bypasses

    • Guard against DNS answers changing between validation and connection.
    • Disable redirects where possible.
    • If redirects are required, reapply scheme, hostname, DNS, and IP-range validation to every redirect target.
    • Set a small maximum redirect count.
  5. Constrain downloaded content

    • Set strict connection, read, and total-operation timeouts.
    • Enforce a maximum response size while streaming.
    • Validate the response Content-Type and verify the actual file signature as a supported image.
    • Reject decompression bombs and images exceeding safe dimension or pixel-count limits.
  6. Apply network-level defense in depth

    • Run import workers with restricted egress.
    • Deny access from the worker network to metadata, management, database, Redis, and other internal service ranges unless explicitly required.
  7. Add security tests

    • Cover loopback and private IPv4 addresses, IPv6 loopback and unique-local addresses, integer and encoded IP forms, metadata endpoints, DNS rebinding, and redirects to prohibited destinations.

...[truncated 99 chars]

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the broader skill pack really embeds a hardcoded HMAC secret and only performs local validation while claiming to be a secure bridge, that creates a trust-boundary problem: operators may deploy or approve it under false assumptions, and any embedded secret could be extracted and abused for request forgery. The danger is amplified by the security-centric branding in this skill, because users may rely on it for sensitive store operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the broader skill pack really embeds a hardcoded HMAC secret and only performs local validation while claiming to be a secure bridge, that creates a trust-boundary problem: operators may deploy or approve it under false assumptions, and any embedded secret could be extracted and abused for request forgery. The danger is amplified by the security-centric branding in this skill, because users may rely on it for sensitive store operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The validator embeds a concrete HMAC secret directly in source code and uses it to compute expected signatures for example requests. In a skill that presents itself as a secure signed API contract, publishing a reusable signing secret undermines the authenticity model if that same secret is used anywhere beyond offline test fixtures, and it normalizes unsafe key-handling practices even if intended only for validation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/environment.md (reported line 29)May include surrounding context.

md
- `LOG_PATH`

## File permissions
- `.env.bridge`: `chmod 600`
- `private.pem`: `chmod 600`
- `public.pem`: readable by the bridge runtime

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/environment.md (reported line 30)May include surrounding context.

md
- `LOG_PATH`

## File permissions
- `.env.bridge`: `chmod 600`
- `private.pem`: `chmod 600`
- `public.pem`: readable by the bridge runtime

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The schema requires product names to contain exactly fr and en, and disallows any other locale keys via additionalProperties: false. This imposes a fixed language policy in the data model without any visible opt-in, fallback, or documentation that the skill is intentionally limited to these locales.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

A hardcoded secret used for HMAC generation is a secret-management flaw regardless of whether it is in validator code, because anyone with repository access can recover it immediately. The surrounding skill context increases concern because the package emphasizes secure signing, so consumers may incorrectly infer that embedding secrets in code is acceptable or, worse, reuse this value in deployments or examples.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This is a manifest-style OpenAPI file, so vague-trigger review applies. The summaries for the write endpoints use broad descriptions like 'Create a product update job', 'Create a product import job', and 'Create an order status update job' without any invocation scope, exclusions, or negative examples, which can make activation boundaries unclear if this spec is used to drive tool selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The JSON example contains a natural-language error message in French: "Stock insuffisant pour la déduction demandée". For a general example file, this suggests a fixed locale without showing any user choice or documented regional constraint, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON example includes French text values like "Nouveau", "Nouvelle description", and a French slug, which imposes a specific language in natural-language content. Because the file provides no indication that the example is locale-specific or that language is configurable, it may conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.