T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fetch_page.py:132- Finding
Unrestricted URL navigation permits access to local and internal resources
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is for webpage analysis, but it gives the browser and file-writing script broader authority than users may expect and can expose sensitive page HTML.
Install only if you will run it in an isolated environment on pages you are authorized to inspect. Do not use it on authenticated, internal, private, or sensitive pages unless you first add URL restrictions, safe temporary-file handling, TLS validation, browser sandboxing, and HTML redaction before any LLM submission.
scripts/fetch_page.py:132Unrestricted URL navigation permits access to local and internal resources
scripts/fetch_page.py:146User-controlled output path can overwrite and delete arbitrary writable files
SKILL.md:27Workflow directs potentially sensitive page HTML to an unspecified LLM
scripts/fetch_page.py:123Browser sandbox and TLS certificate validation are disabled
SKILL.md:22Unpinned Selenium installation creates supply-chain and reproducibility risk
scripts/fetch_page.py:164Error handling persistently stores potentially sensitive page source
The skill description promises broad Selenium automation and page analysis behavior, while the documented workflow mainly fetches page HTML and saves it locally. This mismatch is dangerous because users may trust the high-level description without realizing the concrete behavior includes local persistence of webpage source, which can capture secrets from authenticated pages and expand the skill's effective data-handling footprint.
The skill instructs users to fetch remote webpages and write the HTML to a local output file, but it does not declare any tool scope such as network or file-write permissions. This creates hidden capability risk: an agent or reviewer may underestimate that the skill can exfiltrate page content from remote sites into local storage, including sensitive tokens or authenticated content if misused.
The phraseology around analyzing 'any webpage' and handling generic automation tasks is overly broad and can encourage use against arbitrary targets, including authenticated, internal, or third-party services. In a skill that fetches page source and supports Selenium-based interaction, broad activation language lowers the barrier to misuse for scraping, unauthorized automation, or collection of sensitive HTML content.
The template explicitly instructs users to send downloaded HTML content to a large model but provides no warning about sensitive data that may be present in page source, such as CSRF tokens, hidden form values, internal URLs, user identifiers, or confidential business content. In the context of a skill designed to analyze arbitrary webpages and assist with login/form automation, this omission increases the likelihood of unintended data exfiltration to an external model service.
This Python file contains natural-language descriptions and user-facing output exclusively in Chinese, including the module docstring and command-line interface text. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
The file includes a full Chinese section in addition to the English section, but it does not state whether language selection is user-driven or optional. Because SQP-3 covers language/locale policy violations, presenting a fixed additional locale without an explicit user choice can conflict with organizational expectations around language opt-in.
No suspicious patterns detected.