T09 · Insecure Skill Coding Practices
- Location
scripts/search.sh:322- Finding
Persistent Arbitrary MCP Endpoint Enables Server-Side Request Forgery and Query Disclosure
- Content
View full analysis
"$CONFIG_FILE" || die "写入配置文件失败,请检查文件权限($CONFIG_FILE)" } ``` ```bash # scripts/search.sh:113-137 mcp_post() { local url="$1" body="$2" sid="${3:-}" local hdr_file ct resp hdr_file=$(mktemp) || die "无法创建临时文件" local -a cmd=( curl -s -S -m 30 --connect-timeout 10 -X POST -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' -D "$hdr_file" --data-raw "$body" ) [[ -n "$sid" ]] && cmd+=(-H "Mcp-Session-Id: $sid") cmd+=("$url") if ! resp=$("${cmd[@]}" 2>&1); then rm -f "$hdr_file" die "$resp" fi ``` ```bash # scripts/search.sh:322-327 if $ARG_SAVE; then [[ -z "$ARG_CONFIG" ]] && die "--save 需要配合 -c 传入 MCP JSON 配置" local MCP_URL MCP_URL=$(parse_mcp_url "$ARG_CONFIG") echo "正在检测连通性..." cmd_ping "$MCP_URL" save_url "$MCP_URL" ``` ### Technical Analysis The `--save` workflow extracts a URL from caller-provided JSON, contacts that URL, and then persists it in `scripts/.mcp_url`. The URL is not constrained by an HTTPS requirement, an approved-host allowlist, a permitted-port policy, or destination IP checks. Consequently, the script can be made to issue HTTP requests to an attacker-controlled endpoint or to services reachable from the Agent's network environment, including loopback and private network addresses. The URL is passed safely as one shell-array element, so this is not shell command injection; the vulnerability is the absence of network destination validation. The connectivit ...[truncated 2171 chars]- Remediation
View remediation
