T09 · Insecure Skill Coding Practices
- Location
SKILL.md:44- Finding
Unvalidated Third-Party Sticker Retrieval Can Leak Context and Load Attacker-Controlled URLs
- Content
View full analysis
``` ### Technical Analysis The skill sends a keyword inferred from the current conversation to the third-party domain `api.tangdouz.com`. Because the skill is configured to activate broadly and choose keywords from conversational context, use of the skill discloses context-derived information to an external service without an explicit consent or privacy check. The API response is treated as trusted. In particular, the returned `thumbSrc` field is directly passed to the media-rendering mechanism without validation of: - URL scheme - Destination hostname - Redirect destination - Resolved IP address - Response content type - Response size - Whether the destination belongs to an approved image CDN The effective media destination is therefore controlled by the remote API operator or by an attacker who compromises that service. Depending on how the host platform resolves and renders `MEDIA` URLs, this may result in server-side or client-side requests to attacker-selected destinations. A malicious image URL can also act as a tracking beacon and expose request metadata such as IP address, timestamp, user agent, or referrer information. If the media subsystem performs backend fetching and lacks independent network restrictions, a malicious `thumbSrc` could potentially target loopback, link-local, private-network, or cloud metadata addresses. This latter impact depends on the implementation of the surrounding media renderer and is not established by th ...[truncated 1392 chars]- Remediation
View remediation
