T09 · Insecure Skill Coding Practices
- Location
scripts/run.js:15- Finding
Unrestricted User-Controlled URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
{ if (!t || t.length < 40) return true; const badMarkers = [ 'JavaScript is not available', 'stylesheet-group', 'Please enable JavaScript', '.css-175oi2r', ]; return badMarkers.some((m) => t.includes(m)); }; const tryFetch = async (label, target) => { const r = await fetch(target).catch(() => null); if (!r || !r.ok) { attempts.push({ label, ok: false }); return null; } const t = await r.text(); if (looksBad(t)) { attempts.push({ label, ok: false, reason: 'bad_content' }); return null; } attempts.push({ label, ok: true }); return t; }; let text = await tryFetch('jina', toJina(url)); const sid = extractStatusId(url); if (!text && sid) { text = await tryFetch('fxtwitter-i', `https://api.fxtwitter.com/i/status/${sid}`); if (!text) text = await tryFetch('fxtwitter', `https://api.fxtwitter.com/status/${sid}`); } if (!text) text = await tryFetch('direct', url); return { text: text || '', attempts }; } ``` ### Technical Analysis The Skill claims to process X status URLs, but `--url` is accepted without validating its scheme, hostname, port, or path. If the Jina and FxTwitter attempts do not produce acceptable content, the direct fallback passes the attacker-controlled value to `fetch()`. Consequently, the process can issue HTTP requests from the host or container running the Skill to destinations that an external attacker may not be able to reach directly. Potential targets include: - Loopback services such as `127.0.0.1` and `localhost` - Private network ranges - Link-local services - Cloud instance metadata endpoints - Internal ...[truncated 1956 chars]- Remediation
View remediation
`. 5. Remove the direct arbitrary-URL fallback. Retrieve content only through explicitly approved endpoints. 6. Resolve destination hostnames before connecting and reject loopback, private, link-local, multicast, reserved, and cloud metadata address ranges for both IPv4 and IPv6. 7. Disable redirects or validate the scheme, hostname, and resolved address of every redirect destination. 8. Apply request timeouts, response-size limits, and content-type restrictions. 9. Consider deployment-level egress filtering so the Skill can access only the approved X-content and billing services. 10. Document that post URLs or status identifiers may be sent to Jina AI and FxTwitter, or remove these processors if such disclosure is not intended. ]]>
