T09 · Insecure Skill Coding Practices
- Location
SKILL.md:330- Finding
Server-Side Request Forgery Through Unrestricted Image Fetching
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real temporary media-hosting guide, but it needs review because it can fetch arbitrary URLs from the server and may publicly expose uploader/source metadata.
Review before installing. Only deploy this after restricting remote fetches to trusted domains or blocking private/internal IP ranges and redirects, moving or denying .meta files from the public web root, minimizing IP/source URL/original filename retention, tightening directory permissions, and explicitly approving the sudo and cron steps.
SKILL.md:330Server-Side Request Forgery Through Unrestricted Image Fetching
SKILL.md:84Public Exposure of Source URLs, Original Filenames, and Uploader IP Addresses
SKILL.md:381JSON Metadata Injection Through Unescaped Source URL
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
echo "=== メディアホスティング初期設定 ==="
# ディレクトリ作成
sudo mkdir -p "$media_root"/{temp,uploads,processed,logs,scripts}
# 権限設定
sudo chown -R "$nginx_user:$nginx_user" "$media_root"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
echo "=== メディアホスティング初期設定 ==="
# ディレクトリ作成
sudo mkdir -p "$media_root"/{temp,uploads,processed,logs,scripts}
# 権限設定
sudo chown -R "$nginx_user:$nginx_user" "$media_root"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
echo "=== メディアホスティング初期設定 ==="
# ディレクトリ作成
sudo mkdir -p "$media_root"/{temp,uploads,processed,logs,scripts}
# 権限設定
sudo chown -R "$nginx_user:$nginx_user" "$media_root"
Granting mode 775 to uploads/temp/processed makes those directories group-writable, which can be dangerous in shared-host or multi-service environments. If any other process or user shares the group, files may be modified, replaced, or planted, undermining integrity of hosted content and cleanup/processing logic.
# 権限設定
sudo chown -R "$nginx_user:$nginx_user" "$media_root"
sudo chmod -R 755 "$media_root"
sudo chmod 775 "$media_root"/{uploads,temp,processed}
# 設定ファイル作成
cat > "$media_root/config.env" << 'EOF'
Granting mode 775 to uploads/temp/processed makes those directories group-writable, which can be dangerous in shared-host or multi-service environments. If any other process or user shares the group, files may be modified, replaced, or planted, undermining integrity of hosted content and cleanup/processing logic.
# 権限設定
sudo chown -R "$nginx_user:$nginx_user" "$media_root"
sudo chmod -R 755 "$media_root"
sudo chmod 775 "$media_root"/{uploads,temp,processed}
# 設定ファイル作成
cat > "$media_root/config.env" << 'EOF'
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
local cron_entry="0 2 * * * /var/www/media/scripts/cleanup-ephemeral-media.sh"
# 現在のcrontab取得・更新
(crontab -l 2>/dev/null; echo "$cron_entry") | sort -u | crontab -
echo "cron設定完了: 毎日2時に実行"
}
The skill adds an external URL fetch-and-cache feature that is outside the stated scope of temporary media hosting and introduces server-side retrieval of attacker-controlled URLs. In context, this materially increases risk because it can be used for SSRF-like access, fetching untrusted content for republication, and abuse of the host as a proxy/cache service.
Accepting arbitrary URLs and fetching them with curl enables attacker-influenced outbound network access from the server. Even though the code checks for http/https and limits size/time, it does not prevent requests to internal services, cloud metadata endpoints, or redirected destinations, making this a meaningful SSRF and network abuse risk.
The skill fetches files from third-party URLs and republishes them under a public media domain without clearly warning users in the description. This creates privacy, copyright, and trust risks because operators may unknowingly cause their server to retrieve and publicly host remote content.
The upload handler logs uploader IP addresses and stores request metadata, but the skill description does not prominently disclose this privacy-relevant behavior. In a media-sharing context, silent retention of network identifiers can create compliance, consent, and user-trust issues, especially if logs are broadly accessible or retained longer than expected.
The description, headings, prompts, and user-facing strings are all written in Japanese, with no indication that language selection is optional or that the skill is intentionally limited to a Japanese-only context. Under the policy, forcing a specific language without opt-in is a natural-language locale violation.
No suspicious patterns detected.