Back to skill

Security audit

Safe Web Fetch for Save Token

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent web-fetch tool, but its safety promises are overstated and it can expose sensitive URLs or internal network content in edge cases.

Use this only for clearly public webpages. Do not pass reset links, signed download URLs, internal hostnames, intranet pages, authenticated document links, or URLs containing tokens or keys. Treat its SSRF and sensitive-data protections as incomplete until redirect validation, IPv6 handling, and Jina disclosure controls are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/safe_fetch.py:273
Finding

Secret-Bearing URLs Are Disclosed to Jina Reader

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/safe_fetch.py:234
Finding

SSRF Protection Can Be Bypassed Through Automatically Followed Redirects

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/safe_fetch.py:98
Finding

IPv6 Private and Special-Use Addresses Bypass SSRF Validation

Content
View full analysis
{ip}" ``` ### Technical Analysis `socket.getaddrinfo()` can return both IPv4 and IPv6 addresses. Every IPv6 address passed to `ip_to_int()` fails dotted-IPv4 parsing, causing the function to return `None`. `is_private_ip()` then interprets the parse failure as meaning the address is not private. The code separately rejects the exact hostname `::1`, but it does not comprehensively reject other dangerous IPv6 classes, including: - Unique-local addresses - Link-local addresses - IPv4-mapped IPv6 addresses - Unspecified addresses - Multicast addresses - Reserved or special-use IPv6 ranges As a result, a literal IPv6 URL or a hostname resolving to a non-public IPv6 address may pass validation. If the address is reachable from the Agent host, the direct fallback can connect to it. The security principle violated is fail-safe validation: an address that cannot be parsed by the security routine is treated as permitted instead of denied. ### Att ...[truncated 1155 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
发送前检测页面内容,拒绝发送包含:
- API Keys(`api_key=`, `apikey=`, `key=`)
- Access Tokens(`access_token=`, `token=`)
- Bearer Tokens(`Bearer `, `Authorization: `)
- AWS Keys(`AKIA`, `aws_`)
- Private Keys(`-----BEGIN.*PRIVATE KEY-----`)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises and instructs use of Python-based network fetching and likely local file reads for configuration, but it does not declare any tool scope or permissions boundary. In an agent ecosystem, undeclared capabilities reduce transparency and may allow the skill to be invoked with broader access than reviewers or policy expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The invocation guidance says to use the skill whenever a user needs webpage content, which is overly broad and can cause the agent to send arbitrary user-supplied URLs to an external service. That broad trigger increases the chance of unintended data exfiltration, unsafe fetching of sensitive/internal targets, or bypass of safer built-in decision logic.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises built-in URL whitelist validation as a protection against SSRF, but the configuration leaves allowed_domains empty, which means that control is absent or ineffective unless additional code enforces a safe default. In a web-fetching skill, this discrepancy can allow requests to arbitrary attacker-controlled or internal URLs, undermining the claimed security boundary and increasing SSRF and data-exfiltration risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The function rewrites user-supplied URLs into https://r.jina.ai/http://..., which sends the target URL and causes a third-party service to retrieve and process the destination content. Without clear user-facing disclosure or opt-in, this can expose sensitive URLs, query parameters, internal document locations, or private browsing targets to an external service, contrary to user expectations of a local safety wrapper.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code explicitly disables sensitive-data detection for content fetched through Jina Reader via check_sensitive=False, while the skill description broadly claims sensitive-data protection. This creates a real gap where secrets present in fetched content may be transmitted, processed, and returned without the advertised safeguards, increasing risk of data leakage and unsafe downstream use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description is entirely in Chinese and the document consistently presents usage and instructions only in Chinese, with no indication that language is configurable or based on user preference. This can violate a language/locale policy when a skill implicitly forces one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions, feature list, and usage description are presented in Chinese, which effectively forces a specific language for users reading the built-in documentation. There is no indication of user language choice or justification for a Chinese-only locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.