T09 · Insecure Skill Coding Practices
- Location
scripts/geo_audit.py:194- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a real SEO/GEO auditor, but its local script can make unrestricted network requests from the user's machine and silently weakens HTTPS validation.
Review before installing. Use it only for public websites you intend to audit, avoid private or internal URLs, and be aware that E2E mode may send target domains or prompts to external search providers through local tools. Treat audit results cautiously because the script can accept unauthenticated HTTPS content after a failed verified request.
scripts/geo_audit.py:194Unrestricted URL Fetching Enables Server-Side Request Forgery
scripts/geo_audit.py:42TLS Certificate Verification Is Disabled on Retry
When HTTPS fetches fail, the script silently retries with certificate verification disabled via ssl._create_unverified_context(). That permits man-in-the-middle interception or tampering of fetched HTML, robots.txt, and metadata, causing the audit to trust unauthenticated content and potentially produce incorrect or attacker-influenced results.
The skill instructs the operator to run a local Python script and optionally invoke external search tooling, which implies shell execution and outbound network access, but it does not declare any explicit tool scope or permissions. This creates an authorization ambiguity where an agent or runtime may execute broader capabilities than a reviewer expects, increasing the risk of unintended command execution, network egress, or misuse of local environment resources.
This manifest file is in scope for vague-trigger review, and the description says to use the skill to audit "any target domain's visibility, technical crawlability, and semantic authority" without specifying narrower activation conditions or exclusions. The lack of explicit trigger constraints or negative examples makes invocation boundaries ambiguous for common SEO or website-analysis requests.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
"api": {
"type": "openapi",
"url": "https://api.emergence.science/openapi.json"
},
"discovery": {
"content_index": "https://api.emergence.science/content/index.json"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
"api": {
"type": "openapi",
"url": "https://api.emergence.science/openapi.json"
},
"discovery": {
"content_index": "https://api.emergence.science/content/index.json"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
"api": {
"type": "openapi",
"url": "https://api.emergence.science/openapi.json"
},
"discovery": {
"content_index": "https://api.emergence.science/content/index.json"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
"api": {
"type": "openapi",
"url": "https://api.emergence.science/openapi.json"
},
"discovery": {
"content_index": "https://api.emergence.science/content/index.json"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
"api": {
"type": "openapi",
"url": "https://api.emergence.science/openapi.json"
},
"discovery": {
"content_index": "https://api.emergence.science/content/index.json"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
"api": {
"type": "openapi",
"url": "https://api.emergence.science/openapi.json"
},
"discovery": {
"content_index": "https://api.emergence.science/content/index.json"
Retrying HTTPS requests without certificate validation and without a clear user warning weakens transport security and hides the downgrade from the operator. In this skill context, that makes the GEO/SEO audit easy to manipulate by a network attacker because all subsequent parsing and scoring rely on potentially forged responses.
The skill can execute locally installed external binaries (including a hard-coded user-specific fallback path) during auditing, which expands its capabilities from passive website inspection to local code/tool execution. In an agent environment, this is more dangerous because it can trigger unintended side effects, leak query data to third-party tools, or invoke an attacker-replaced binary if the expected executable path is not trustworthy.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# Check domain indexation
cmd_index = [bx_path, "web", f"site:{domain}"]
try:
res = subprocess.run(cmd_index, capture_output=True, text=True, timeout=15)
if res.returncode == 0:
data = json.loads(res.stdout)
results = data.get("web", {}).get("results", [])
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# Check domain indexation
cmd_index = [bx_path, "web", f"site:{domain}"]
try:
res = subprocess.run(cmd_index, capture_output=True, text=True, timeout=15)
if res.returncode == 0:
data = json.loads(res.stdout)
results = data.get("web", {}).get("results", [])
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if prompt:
cmd_rank = [bx_path, "web", prompt]
try:
res = subprocess.run(cmd_rank, capture_output=True, text=True, timeout=15)
rank = -1
found_url = None
if res.returncode == 0:
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if prompt:
cmd_rank = [bx_path, "web", prompt]
try:
res = subprocess.run(cmd_rank, capture_output=True, text=True, timeout=15)
rank = -1
found_url = None
if res.returncode == 0:
The README explicitly advertises live queries to external search services but does not warn users that running the tool may transmit target domains, prompts, and related metadata to third-party providers. This is not inherently malicious, but it creates a transparency and privacy issue because operators may unintentionally disclose sensitive client, internal, or prelaunch information during use.
The file path and title indicate an English-specific version of the skill content (..._en.md), but the document provides no user-facing language choice or explanation for why English is required. Under the policy, forcing a specific language without opt-in can be a natural-language locale violation.
Detected: suspicious.insecure_tls_verification