T09 · Insecure Skill Coding Practices
- Location
SKILL.md:36- Finding
Shell Command Injection Through Untrusted URL Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent URL-to-markdown purpose, but its shell-command examples can execute unsafe user-supplied URL text and it forwards complete URLs to third-party services without enough user-side safeguards.
Install only if you are comfortable having supplied URLs sent to markdown.new or r.jina.ai. Do not use it for private intranet pages, localhost URLs, signed download links, password-reset or invite links, or URLs containing access tokens unless the skill is revised to validate URLs and avoid shell-string interpolation.
SKILL.md:36Shell Command Injection Through Untrusted URL Interpolation
SKILL.md:36Disclosure of Complete User-Provided URLs to Third-Party Extraction Services
The skill instructs the agent to send user-provided URLs to third-party services (markdown.new and r.jina.ai) but does not require any user-facing disclosure or consent before doing so. URLs can contain sensitive query parameters, private document links, internal hostnames, or access tokens, so forwarding them to external services can leak confidential information and browsing intent.
No suspicious patterns detected.