T09 · Insecure Skill Coding Practices
- Location
scripts/save_paper.py:97- Finding
Insufficient URL Validation Enables Server-Side Request Forgery and Unintended Data Upload
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Zotero paper-saving skill is mostly coherent, but it needs Review because it can automatically fetch a URL-derived PDF and upload it to Zotero using the user's API credentials.
Review this skill before installing. Use a least-privilege Zotero API key, expect it to create Zotero items and upload attachments, and avoid processing untrusted paper URLs unless the PDF download logic is tightened to accept only canonical HTTPS arxiv.org URLs with size and content validation.
scripts/save_paper.py:97Insufficient URL Validation Enables Server-Side Request Forgery and Unintended Data Upload
scripts/save_paper.py:2Unpinned Runtime Dependency Permits Unreviewed Supply-Chain Changes
The skill advertises behavior that requires environment-variable access and network communication, but it does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens transparency and policy enforcement, making it harder for users or the platform to understand that credentials will be read and data will be transmitted to Zotero.
This code forces a specific language in its command-line description and help text, which is a natural-language policy concern when no user opt-in or locale justification is provided. The same pattern continues in runtime messages, indicating the skill assumes Chinese-only interaction by default.
The script behavior exceeds the declared skill scope by automatically downloading a PDF from arXiv and uploading it to Zotero as an attachment. This creates an integrity and trust problem: users or calling agents may believe the skill only saves metadata, while it also performs external network retrieval and content ingestion, which can introduce unreviewed files into a user's library and trigger unexpected data transfer.
The skill instructs users to store Zotero credentials in ZOTERO_CREDENTIALS, but it does not clearly warn that those credentials will be used to authenticate outbound requests that transmit paper metadata and possibly summaries to Zotero. This is a disclosure/consent weakness: users may provide secrets without fully understanding the external data flow.
All user-facing natural-language content in the manifest description and markdown instructions is in Chinese, and there is no indication that users may interact in another language or that the locale restriction is intentional. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.
No suspicious patterns detected.