T09 · Insecure Skill Coding Practices
- Location
templates/http-llm-workflow.yaml:123- Finding
Untrusted Remote API Content Is Passed Directly to an LLM
- Content
View full analysis
Vulnerability Details
File Location:
templates/http-llm-workflow.yaml, lines 123-125 and 154-177, with the unsafe prompt interpolation at lines 257-274
Vulnerability Type: Indirect prompt injection through untrusted remote content
Risk Level: MediumVulnerable Code
yaml url: https://api.example.com/resource params: "id:{{#1700000000001.resource_id#}}" headers: "Authorization:Bearer {{#env.API_KEY#}}"yaml code: | import json def main(response_body, status_code): """Parse API response and extract data.""" result = { "success": False, "content": "", "error_message": "" } # Check status code if status_code != 200: result["error_message"] = f"API returned status {status_code}" return result # Parse JSON if not response_body: result["error_message"] = "Empty response" return result try: data = json.loads(response_body) if data.get("success"): result["success"] = True result["content"] = data.get("content", "") else: result["error_message"] = data.get("message", "Unknown error") except json.JSONDecodeError as e: result["error_message"] = f"JSON parse error: {str(e)}" return resultyaml prompt_template: - id: system-prompt role: system text: | You are an expert content analyst. Analyze the provided content and provide insights. - id: user-prompt role: user text: | Please analyze the following content: {{#1700000000003.content#}} Provide: 1. Summary (2-3 sentences) 2. Key points (bullet list) 3. Quality score (1-10)Technical Analysis
The workflow retrieves content from an external API, extracts the response's
contentf ...[truncated 2666 chars]- Remediation
View remediation
Remediation Suggestions
- Treat every external response as untrusted input, even when it comes from an authenticated API.
- Add an explicit system-level rule stating that retrieved content is data only and that any instructions, requests, or policy text inside it must not be followed.
- Place the remote content inside clear delimiters such as XML-style data tags and describe those delimiters in the system prompt.
- Validate the response schema and impose a conservative maximum length before sending content to the model.
- Apply allowlist-based validation where the expected content format permits it; reject unexpected fields or content types.
- Keep the analysis LLM isolated from tools that can execute commands, access secrets, modify workflows, send messages, or perform privileged network operations.
- If the output drives automated actions, validate it against a strict structured-output schema and require independent policy checks or human approval.
- Require users to replace and verify
api.example.combefore import. Document that the configured endpoint receives both the API credential and resource identifier. - Restrict outbound HTTP access to approved hosts and HTTPS destinations at the Dify deployment or network layer.
- Use a narrowly scoped API key with only the permissions required to read the intended resource, and rotate it if it is ever sent to an untrusted destination.
