T09 · Insecure Skill Coding Practices
- Location
SKILL.md:23- Finding
Untrusted QR URLs Can Receive Sensitive Invoice and Banking Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:23-53
Vulnerability Type: Unvalidated external URL navigation followed by sensitive-data submission
Risk Level: HighVulnerable Instructions
text ### Step 2: Navigate to Invoice System 1. Open the decoded URL in browser automation 2. Verify the page loads successfully 3. Take snapshot to understand form structure ### Step 3: Retrieve Company Information Before filling the form, retrieve the user's company information: 1. Check memory files for stored invoice header information: - Search `memory/YYYY-MM-DD.md` for recent invoice info - Check `MEMORY.md` for long-term stored details 2. Required fields typically include: - Company name (公司名称) - Tax ID/Unified Social Credit Code (税号) - Address (地址) - Phone number (电话) - Bank name (开户行) - Bank account number (银行账号) ### Step 4: Fill Invoice Form 1. Analyze the form structure using browser snapshot 2. Fill in company information fields 3. Fill in recipient information: - Phone number (手机号) - Email address (邮箱) 4. Verify all required fields are completedTechnical Analysis
The decoded QR value is treated as a navigable URL without a mandatory validation procedure. The workflow does not enforce:
- An
https://scheme. - A trusted invoice-provider domain allowlist.
- Rejection of embedded credentials, IP-address hosts, private network destinations, or nonstandard ports.
- Validation of redirect destinations.
- A binding between the expected invoice provider and the final page origin.
- Explicit user approval before sensitive fields are entered.
After navigation, the Agent is instructed to infer the form structure and populate it with company identity, tax, bank-account, phone, and email information obtained from memory. A malicious page can imitate an invoice form and expose field labels that cause the Agent to enter this infor ...[truncated 1568 chars]
- An
- Remediation
View remediation
Remediation Suggestions
- Parse the decoded value as a URL and accept only canonical
https://URLs. - Maintain an explicit allowlist of approved invoice-provider hostnames; do not rely on visual page appearance.
- Reject URLs containing credentials, IP-literal hosts, loopback destinations, link-local destinations, private-network destinations, nonstandard ports, and unsupported schemes.
- Validate every redirect and stop navigation if any redirect leaves the allowlist.
- Display the final normalized origin and requested fields to the user.
- Require explicit user confirmation immediately before entering or submitting tax, banking, phone, or email data.
- Use provider-specific field mappings instead of filling fields inferred solely from page labels.
- Minimize submitted data and omit bank information unless the selected trusted provider demonstrably requires it.
- Isolate browser automation from local services and private networks where feasible.
- Parse the decoded value as a URL and accept only canonical
