T09 · Insecure Skill Coding Practices
- Location
SKILL.md:1- Finding
Unvalidated User-Supplied URL Passed to Network Fetch Tool
- Content
View full analysis
- Remediation
View remediation
str: parsed = urlparse(raw_url) if parsed.scheme != "https": raise ValueError("Only HTTPS URLs are permitted") if parsed.hostname != "zernio.com": raise ValueError("Only zernio.com URLs are permitted") if parsed.username or parsed.password or parsed.port not in (None, 443): raise ValueError("Credentials and nonstandard ports are prohibited") prefix = "/user/" if not parsed.path.startswith(prefix): raise ValueError("Not a Zernio profile URL") profile_id = parsed.path[len(prefix):].strip("/") if not PROFILE_ID_RE.fullmatch(profile_id): raise ValueError("Invalid profile identifier") return f"https://zernio.com/user/{quote(profile_id, safe='')}" ``` 8. Update the Skill instructions to state that `web_fetch` may only receive a canonical, validated Zernio URL. 9. Apply network-layer egress controls so the fetch tool cannot access private or metadata-service address ranges even if application validation fails. 10. Add tests c ...[truncated 159 chars]
