T09 · Insecure Skill Coding Practices
- Location
scripts/publish.py:73- Finding
Unrestricted Cleartext MCP Communication with Forced Proxy Bypass
- Content
View full analysis
Vulnerability Details
File Location:
scripts/publish.py, lines 73–82 and 95–102
Vulnerability Type: Unvalidated backend URL, permitted cleartext transport, and forced proxy bypass
Risk Level: MediumVulnerable Code
python def curl(payload, session=None, timeout=300): """Send an MCP JSON-RPC request and return the response body.""" cmd = [ "curl", "--noproxy", "*", "-s", "--max-time", str(timeout), "-X", "POST", MCP_URL, "-H", "Content-Type: application/json", ] if session: cmd += ["-H", "Mcp-Session-Id: {}".format(session)] cmd += ["-d", json.dumps(payload, ensure_ascii=False)]python cmd = [ "curl", "--noproxy", "*", "-s", "-i", "--max-time", "30", "-X", "POST", MCP_URL, "-H", "Content-Type: application/json", "-d", json.dumps(init_payload), ]Technical Analysis
The script obtains
MCP_URLfrom theMCP_PUBLISHER_URLenvironment variable orconfig.jsonbut does not validate its scheme, host, port, or destination. Plain HTTP is explicitly supported by the documented example.Both request paths also use
curl --noproxy "*". This forces every MCP request to bypass configured HTTP and HTTPS proxies, even when the endpoint is remote. As a result, organizational egress controls, monitoring gateways, or security proxies that the execution environment expects to apply are bypassed.The script transmits MCP initialization data, publication titles and bodies, tags, local image path strings, and MCP session identifiers through this channel. It also accepts session identifiers and profile responses from the configured endpoint. When a non-loopback endpoint uses HTTP, an on-path attacker can observe or modify these exchanges.
Using
subprocess.run()with an argument array prevents shell metacharacters inMCP_URLfrom becoming ordinary shell command injection. The confirmed issue is therefore insecure destination and transport handling, not shell injection. ...[truncated 1536 chars]- Remediation
View remediation
Remediation Suggestions
- Parse the configured URL with a strict URL parser before invoking
curl. - Permit only
httpsfor non-loopback destinations. If local development requires HTTP, restrict it to explicit loopback hosts such as127.0.0.1,[::1], or a carefully validatedlocalhost. - Reject URLs with unsupported schemes, missing hosts, embedded credentials, fragments, or malformed ports.
- Remove
--noproxy "*". Respect the host environment's proxy policy by default. - If proxy bypass is necessary for local services, apply it only after validating that the destination resolves exclusively to an approved loopback address.
- Preserve TLS certificate and hostname verification; do not introduce
curl --insecure. - Consider an explicit endpoint allowlist for automated or managed deployments.
- Check
curlreturn codes and standard error, and fail closed on TLS, transport, or HTTP errors rather than treating an empty or malformed response as ordinary output. - Avoid printing the full configured URL if it can contain credentials or sensitive query parameters.
- Document the security boundary clearly: the configured MCP backend receives publication data and should be trusted and authenticated.
- Parse the configured URL with a strict URL parser before invoking
