T09 · Insecure Skill Coding Practices
- Location
scripts/safe_fetch.py:273- Finding
Secret-Bearing URLs Are Disclosed to Jina Reader
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent web-fetch tool, but its safety promises are overstated and it can expose sensitive URLs or internal network content in edge cases.
Use this only for clearly public webpages. Do not pass reset links, signed download URLs, internal hostnames, intranet pages, authenticated document links, or URLs containing tokens or keys. Treat its SSRF and sensitive-data protections as incomplete until redirect validation, IPv6 handling, and Jina disclosure controls are fixed.
scripts/safe_fetch.py:273Secret-Bearing URLs Are Disclosed to Jina Reader
scripts/safe_fetch.py:234SSRF Protection Can Be Bypassed Through Automatically Followed Redirects
scripts/safe_fetch.py:98IPv6 Private and Special-Use Addresses Bypass SSRF Validation
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
发送前检测页面内容,拒绝发送包含:
- API Keys(`api_key=`, `apikey=`, `key=`)
- Access Tokens(`access_token=`, `token=`)
- Bearer Tokens(`Bearer `, `Authorization: `)
- AWS Keys(`AKIA`, `aws_`)
- Private Keys(`-----BEGIN.*PRIVATE KEY-----`)
The skill advertises and instructs use of Python-based network fetching and likely local file reads for configuration, but it does not declare any tool scope or permissions boundary. In an agent ecosystem, undeclared capabilities reduce transparency and may allow the skill to be invoked with broader access than reviewers or policy expect.
The invocation guidance says to use the skill whenever a user needs webpage content, which is overly broad and can cause the agent to send arbitrary user-supplied URLs to an external service. That broad trigger increases the chance of unintended data exfiltration, unsafe fetching of sensitive/internal targets, or bypass of safer built-in decision logic.
The skill advertises built-in URL whitelist validation as a protection against SSRF, but the configuration leaves allowed_domains empty, which means that control is absent or ineffective unless additional code enforces a safe default. In a web-fetching skill, this discrepancy can allow requests to arbitrary attacker-controlled or internal URLs, undermining the claimed security boundary and increasing SSRF and data-exfiltration risk.
The function rewrites user-supplied URLs into https://r.jina.ai/http://..., which sends the target URL and causes a third-party service to retrieve and process the destination content. Without clear user-facing disclosure or opt-in, this can expose sensitive URLs, query parameters, internal document locations, or private browsing targets to an external service, contrary to user expectations of a local safety wrapper.
The code explicitly disables sensitive-data detection for content fetched through Jina Reader via check_sensitive=False, while the skill description broadly claims sensitive-data protection. This creates a real gap where secrets present in fetched content may be transmitted, processed, and returned without the advertised safeguards, increasing risk of data leakage and unsafe downstream use.
The manifest description is entirely in Chinese and the document consistently presents usage and instructions only in Chinese, with no indication that language is configurable or based on user preference. This can violate a language/locale policy when a skill implicitly forces one language without opt-in.
The natural-language instructions, feature list, and usage description are presented in Chinese, which effectively forces a specific language for users reading the built-in documentation. There is no indication of user language choice or justification for a Chinese-only locale.
No suspicious patterns detected.