T09 · Insecure Skill Coding Practices
- Location
scripts/scrapling_scrape.py:41- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
None: p = argparse.ArgumentParser() p.add_argument("--url", required=True) p.add_argument("--mode", choices=["fetcher", "dynamic", "stealthy"], default="fetcher") p.add_argument("--css", help="CSS selector (supports ::text and ::attr())") p.add_argument("--xpath", help="XPath selector") p.add_argument("--first", action="store_true", help="Return only the first match") p.add_argument("--headless", action="store_true", help="Headless browser (dynamic/stealthy)") p.add_argument("--solve-cloudflare", action="store_true", help="Attempt to solve Cloudflare (stealthy session)") p.add_argument("--network-idle", action="store_true", help="Wait for network idle (dynamic session)") p.add_argument("--adaptive", action="store_true", help="Use adaptive selectors (if supported)") p.add_argument("--auto-save", action="store_true", help="Auto-save selector fingerprints (if supported)") p.add_argument("--pretty", action="store_true", help="Pretty-print JSON") args = p.parse_args() if not args.css and not args.xpath: _die("Provide --css or --xpath") url = args.url try: # Sessions are more reliable than one-shot fetchers for anything non-trivial. from scrapling.fetchers import FetcherSession, DynamicSession, StealthySession except Exception: _die( "Scrapling is not installed in this Python environment. Try:\n" " python3 -m pip install scrapling\n" "If you need browser-based fetching, you may also need:\n" " python3 -m playwright install chromium" ) if args.mode == "fe ...[truncated 4726 chars]- Remediation
View remediation
