T09 · Insecure Skill Coding Practices
- Location
scripts/jable_downloader.py:28- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it claims, but its downloader can be steered to contact non-Jable URLs and pass unvalidated remote media URLs into a local downloader.
Install only if you are comfortable with a skill that downloads adult media, creates organized folders under your Videos directory, uses external tools, and makes network requests. Before use, restrict inputs to known Jable video IDs or Jable.tv URLs, consider a dedicated output folder, and prefer pinned/trusted installations of yt-dlp and ffmpeg. The publisher should add URL/media validation and explicit permission scoping before this is treated as low-risk.
scripts/jable_downloader.py:28Unrestricted URL Fetching Enables Server-Side Request Forgery
scripts/jable_downloader.py:43Untrusted HLS Value Is Passed to yt-dlp Without URL or Argument Validation
SKILL.md:12Third-Party Downloader Dependency Is Installed Without Version or Integrity Pinning
The skill advertises behavior that requires network access, shell execution, and filesystem interaction, but it does not declare any explicit tool scope or permissions. This weakens reviewability and user consent because an agent may exercise powerful capabilities not clearly bounded by the manifest.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Before using, ensure these tools are installed:
- **yt-dlp** — Video download engine (`pip install yt-dlp` or `brew install yt-dlp`)
- **ffmpeg** — Video processing (`sudo apt install ffmpeg` or `brew install ffmpeg`)
- **xdg-user-dir** — (Linux only) For finding default Videos folder
## Usage
The skill writes files into the user's Videos folder and reorganizes them by actress name, but the description does not foreground this as a side effect requiring clear user awareness. Silent or under-disclosed file creation can lead to privacy issues, unwanted disk consumption, and user surprise, especially given the sensitive nature of the content being downloaded.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
system = platform.system()
if system == "Linux":
try:
res = subprocess.run(['xdg-user-dir', 'VIDEOS'], capture_output=True, text=True, check=True)
path = Path(res.stdout.strip())
if path.exists(): return str(path)
except: pass
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd = ['yt-dlp', '--force-ipv4', '--concurrent-fragments', '16', '--referer', 'https://jable.tv/', '-o', output_path, m3u8_url]
print(f"⬇️ Downloading: {title} (attempt {attempt + 1}/{max_retries})")
process = subprocess.Popen(cmd, stdout=subprocess.PIPE, stderr=subprocess.STDOUT, text=True, bufsize=1)
for line in process.stdout:
if '[download]' in line:
The script makes HTTP requests to jable.tv to retrieve page content and later downloads media data, but there is no docstring, comment, or upfront warning that running the tool will contact an external service and transmit requested video identifiers/search terms. The existing progress prints describe activity after execution begins, but they do not function as a disclosure of the privacy/network behavior.
The script creates directories, writes downloaded MP4 files, moves them into actress-named folders, and deletes temporary files, but there is no user-facing warning or documentation describing these filesystem changes before they occur. Although some status messages appear during cleanup and download, they do not clearly disclose the full extent of file modifications in advance.
No suspicious patterns detected.