Back to skill

Security audit

Wget Tool

Security checks for vulnerabilities and agentic risk

Overview

This downloader is purpose-aligned, but it needs review because it is less bounded and less capable than documented and can read from unexpected URL schemes or overwrite writable files.

Review before installing. Use only with trusted URLs and output paths, do not pass real secrets in command-line headers, and avoid automated or unattended use until the tool enforces allowed schemes, safer destination handling, and accurate documentation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wget.py:3
Finding

Unrestricted URL Schemes and Arbitrary File Overwrite

Content
View full analysis
[-O output]"); sys.exit(1) urllib.request.urlretrieve(url, output or os.path.basename(url)) print("Downloaded") ``` ### Technical Analysis The script passes the supplied URL directly to `urllib.request.urlretrieve` without validating its scheme. Although `SKILL.md` declares support for HTTP, HTTPS, and FTP downloads, the implementation does not enforce that protocol boundary. Python URL handlers may accept local resources such as `file://` URLs, allowing the script to copy files readable by its operating-system account. The output value is also passed directly to `urlretrieve` without restricting it to an approved download directory. A caller who controls the arguments can consequently select an absolute path or a path containing traversal components and replace a writable file. There is no existing-file check, overwrite confirmation, canonical-path boundary check, or symlink defense. The custom `-O` parser is defective because it enumerates `sys.argv[1:]` but reads `sys.argv[i+3]`. Normal documented usage such as `wget.py URL -O output` raises `IndexError`. Because unknown options are silently ignored and later positional arguments replace the URL, a crafted argument sequence can nevertheless assign both a chosen output and a chosen source. ### Attack Path 1. The attacker obtains control over arguments supplied to the downloader. 2. The attacker supplies a local `file://` URL instead of a documented network URL. 3. The attacker crafts the unusual argument order needed by the broken parser, for example: ```bash python3 scripts/wget.py -O --dummy ...[truncated 1338 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation advertises capabilities such as resume, recursion, rate limiting, and progress feedback that static analysis says are not actually implemented. This mismatch can cause users or agents to rely on safety or operational properties that do not exist, which may lead to uncontrolled downloads, incomplete transfers, or unexpected behavior during automated use.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documents network downloading capabilities and implies shell execution behavior, but it does not declare any explicit tool scope or permissions boundaries. This increases the risk of over-broad execution in an agent environment, making it harder to enforce least privilege or audit what external access the skill requires.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example shows a bearer token passed directly on the command line, which can expose credentials through shell history, process listings, logs, CI output, and agent traces. In an agent skill context, this is especially risky because prompts, transcripts, and execution metadata may be retained or shared across systems.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
wget-tool -r -l 2 https://docs.example.com/

# Custom headers and user-agent
wget-tool https://api.example.com/data.json \
  --header "Authorization: Bearer token123" \
  --user-agent "MyScript/1.0"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a feature-rich wget-like downloader, but the code only performs a single basic urlretrieve call and prints a generic completion message. Nothing in the file implements resume, recursion/mirroring, rate limiting, or progress reporting, creating a clear mismatch between the claimed behavior and actual functionality.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.