T09 · Insecure Skill Coding Practices
- Location
SKILL.md:47- Finding
Unrestricted User-Supplied URL Navigation in an Authenticated Browser Session
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:47-57,SKILL.md:82,SKILL.md:98-100, andSKILL.md:144-146
Vulnerability Type: Unvalidated URL navigation
Risk Level: MediumVulnerable Snippets
SKILL.md:47-57:text detail [URL] detail https://kns.cnki.net/kcms2/article/abstract?xxx download pdf [URL] download caj [URL]SKILL.md:82andSKILL.md:98-100instruct the browser workflow to navigate to a supplied paper URL before checking authentication state or CAPTCHA conditions.SKILL.md:144-146requires Chrome with browser automation and recommends retaining the authenticated session.Technical Analysis
The skill accepts arbitrary URLs for its
detail,download, andexportworkflows but does not define any URL validation or destination restrictions. The CNKI URL shown in the examples is illustrative and does not enforce a security boundary.A secure implementation should parse the supplied URL and enforce an explicit allowlist of required official CNKI hosts. It should also restrict the scheme to HTTPS, reject embedded credentials and unexpected ports, and verify redirect destinations. Without these controls, schemes such as
file:,data:, orjavascript:, unrelated HTTPS domains, and redirects to attacker-controlled hosts are not explicitly prohibited.The exposure is amplified by the recommendation to keep Chrome logged in. Browser same-origin controls ordinarily prevent an unrelated website from directly reading CNKI cookies, but they do not prevent the browser automation agent from processing hostile page content, initiating unintended downloads, encountering phishing content, or being influenced by instructions rendered on an attacker-controlled page.
Attack Path
- An attacker or untrusted input source supplies a
detail,download, orexportcommand containing a URL outside the legitimate CNKI domain. - The skill follows its documented workflow and ...[truncated 1177 chars]
- An attacker or untrusted input source supplies a
- Remediation
View remediation
Remediation Suggestions
- Parse every supplied URL with a standards-compliant URL parser before browser navigation.
- Permit only the
https:scheme. Explicitly rejecthttp:,file:,data:,javascript:, and all other schemes. - Define a minimal hostname allowlist containing only the official CNKI hosts required by each operation, such as
kns.cnki.net. - Compare normalized hostnames exactly. Do not use substring checks that would accept domains such as
kns.cnki.net.attacker.example. - Reject URLs containing embedded usernames or passwords, unexpected ports, malformed hostnames, or ambiguous encoded characters.
- Validate the final destination after every redirect and terminate navigation if any redirect leaves the allowlist.
- Require explicit user confirmation before initiating a file download or navigating outside the expected page flow.
- Use a dedicated browser profile containing no unrelated authenticated sessions or sensitive browsing state.
- Treat all page content as untrusted data and prohibit webpage text from changing tool permissions, security rules, or the task objective.
- Add automated tests covering malicious domains, subdomain confusion, encoded hostnames, unsupported schemes, embedded credentials, and cross-domain redirects.
