T09 · Insecure Skill Coding Practices
- Location
scripts/html-to-pdf.js:19- Finding
Unrestricted URL Rendering Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This HTML-to-PDF skill does what it claims, but its URL conversion can fetch arbitrary network targets from the user's machine without documented safeguards.
Review before installing. Use this only for trusted local HTML or trusted public URLs, avoid converting internal/private/metadata URLs, choose output paths carefully, and prefer running it in a container or network-restricted environment. Pin Puppeteer with a lockfile and avoid bypassing macOS quarantine unless the browser binary is verified from a trusted source.
scripts/html-to-pdf.js:19Unrestricted URL Rendering Enables Server-Side Request Forgery
SKILL.md:84Unpinned Puppeteer Installation Creates Supply-Chain Exposure
Referenced artifact was not completely inspected
node scripts/html-to-pdf.js input.html output.pdf
Referenced artifact was not completely inspected
node scripts/html-to-pdf.js input.html output.pdf
Referenced artifact was not completely inspected
node scripts/html-to-pdf.js input.html output.pdf
Referenced artifact was not completely inspected
node scripts/html-to-pdf.js input.html output.pdf
The skill explicitly supports converting remote URLs, which causes the host running Puppeteer to make outbound network requests to third-party sites. Without a warning, users may unknowingly expose IP address, user agent, timing, and possibly authenticated network reachability or internal URL access patterns, which is a meaningful security and privacy risk in an agent environment.
The setup guide advises users to remove the macOS quarantine attribute from a Chrome binary without explaining the trust implications or constraining it to a verified source. Quarantine exists to warn about untrusted downloaded executables, and instructing users to bypass it can normalize running potentially unsafe binaries and reduce host protections.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
sudo apt-get install -y libgconf-2-4 \
libnss3 libxss1 libasound2 libappindicator1 libindicator7 xdg-utils fonts-liberation
# Fedora
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
sudo apt-get install -y libgconf-2-4 \
libnss3 libxss1 libasound2 libappindicator1 libindicator7 xdg-utils fonts-liberation
# Fedora
The examples show writing a PDF to a user-supplied output path, but the documentation does not warn that running the tool will create or overwrite local files. In an agent workflow, this can lead to unintended file modification, clobbering existing documents, or writing sensitive output to unsafe locations if path handling is not carefully controlled.
The skill description states it can convert an HTML file or URL to a PDF and write the result to an output path, which implies both network access for URLs and file creation on disk. The markdown does not include any warning or disclosure about these behaviors' potential privacy or system-impact implications.
No suspicious patterns detected.