T09 · Insecure Skill Coding Practices
- Location
scripts/extract_article.py:22- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a read-later tool, but it asks for broad URL, file, and credential-related workflows with weak scoping and some unsafe or unsupported behavior.
Review this carefully before installing. Use it only with URLs and files you trust, avoid giving service passwords or tokens until credential handling is clarified, do not rely on the advertised unsupported features, and be aware that saved library data is written under your home directory and deletions are irreversible from the tool.
scripts/extract_article.py:22Unrestricted URL Fetching Enables Server-Side Request Forgery
scripts/convert_format.py:11Unescaped Markdown and Metadata Allow Active-Content Injection in Generated Documents
\1\1',
...[truncated 2877 chars]The documented behavior and the detected capabilities do not align: the skill claims extensive offline storage, export, organization, and sync features, while analysis indicates those functions are not actually implemented and that outbound network access occurs without declared permissions. This mismatch is dangerous because users may trust the skill with URLs, files, or credentials under false assumptions about what it does, masking unexpected data transmission or incomplete processing.
The skill advertises capabilities that require network, file read, and file write behavior, but it declares no explicit tool scope or permissions. This creates a trust and review gap: an agent or reviewer cannot easily determine what external access the skill will need, increasing the chance of unintended data access or exfiltration through URL fetching, local article storage, and import operations.
The 'use when' scope is so broad that the skill may be invoked for many generic reading, note-taking, or organization requests, increasing the chance of unnecessary network fetches, file writes, or credential-handling workflows. Over-broad routing is a security concern because it expands the situations in which the skill can access sensitive URLs, local content, or third-party integrations without sufficiently specific user intent.
The documentation instructs users to provide service credentials and fetch remote URLs but does not warn that these actions transmit data to external services and may store sensitive tokens or imported content locally. In a skill that handles article retrieval and third-party imports, missing disclosure materially increases the risk of users exposing credentials, private reading history, or sensitive URLs without informed consent.
Advertising a '--full-content' option to attempt paywall bypass introduces a capability unrelated to a normal read-later workflow and signals intentional circumvention of publisher access controls. Even if experimental, this increases legal, policy, and abuse risk and could encourage the skill to retrieve content in ways users and platform owners do not expect.
The delete command performs a destructive operation by invoking article deletion and then only reports success after the fact. There is no confirmation prompt, pre-deletion warning, or other user disclosure in the CLI flow before data is permanently removed.
No suspicious patterns detected.