Back to skill

Security audit

Social Post Generator Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed social-post helper, but it can make unrestricted web requests to any user-supplied URL from the agent environment.

Install only if you are comfortable with the skill making outbound requests to URLs you provide. Do not use it with private, internal, localhost, cloud-metadata, or sensitive draft URLs unless the runtime blocks private-network egress or the skill is updated to validate destinations and limit redirects.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate.sh:19
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery in Post Generation

Content
View full analysis

Vulnerability Details

File Location: scripts/generate.sh:19-24
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: Medium

Vulnerable Code:

bash
if echo "$input" | grep -qE '^https?://'; then
  echo "Fetching article: $input" >&2
  content=$(curl --silent --max-time 20 -L \
    -H "User-Agent: Mozilla/5.0" \
    "$input" 2>&1)

Technical Analysis

The script treats any string beginning with http:// or https:// as an article URL and passes it directly to curl. It does not validate the hostname, resolved IP address, destination port, or URL redirect chain.

The -L option follows redirects automatically. Consequently, validating only the original URL scheme is insufficient: an attacker can provide either a direct internal URL or a public URL that redirects to a loopback, link-local, private-network, or cloud metadata address.

Retrieving public article content is required by the declared functionality. However, allowing arbitrary access to network locations unavailable to the caller exceeds the minimum network privileges required by the Skill.

The code does not collect credentials or transmit environment variables. The security issue is unrestricted destination access rather than deliberate sensitive-data exfiltration.

Attack Path

  1. An attacker supplies a URL such as an internal service address, cloud metadata endpoint, or attacker-controlled public URL.
  2. The Agent invokes scripts/generate.sh with that URL.
  3. curl -L sends the request from the Agent host and follows any redirects without validating their destinations.
  4. The request can reach services on loopback, private networks, or link-local networks that are inaccessible to the external attacker.
  5. The response is stored in content and parsed for its title, description, and body.
  6. Parsed title or description data may be included in generated output, while other response characteristics can ...[truncated 665 chars]
Remediation
View remediation

Remediation Suggestions

  • Permit only the https scheme unless plain HTTP is explicitly required.
  • Parse URLs with a dedicated URL parser rather than relying only on a regular-expression prefix check.
  • Resolve the destination hostname before connecting and reject IPv4 and IPv6 addresses in loopback, private, link-local, multicast, unspecified, documentation, and reserved ranges.
  • Restrict destination ports to an explicit allowlist, preferably ports 80 and 443.
  • Disable redirects where possible. If redirects are necessary, resolve and validate every redirect destination before following it.
  • Protect against DNS rebinding by ensuring the validated address is the address used for the connection.
  • Run article retrieval in a sandbox with egress rules that block internal networks and cloud metadata endpoints.
  • Apply response-size limits in addition to the existing time limit.
  • Return a clear error when destination validation fails, without exposing internal connection details.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/thread.sh:18
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery in Thread Generation

Content
View full analysis

Vulnerability Details

File Location: scripts/thread.sh:18-23
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: Medium

Vulnerable Code:

bash
if echo "$input" | grep -qE '^https?://'; then
  echo "Fetching article: $input" >&2
  content=$(curl --silent --max-time 20 -L \
    -H "User-Agent: Mozilla/5.0" \
    "$input" 2>&1)

Technical Analysis

The caller controls the complete URL passed to curl. The implementation checks only whether the input begins with an HTTP or HTTPS scheme. It does not restrict hosts, resolved addresses, ports, or redirect destinations.

Because curl is invoked with -L, an attacker-controlled public endpoint can redirect the request to an internal destination. This permits the script to act as an SSRF client from the Agent host.

Network access is necessary to process public article URLs, but access to loopback, private-network, link-local, and metadata services is not necessary for thread generation and violates least-privilege principles.

No code in the inspected script sends local files, environment variables, credentials, or other independently collected secrets to the destination.

Attack Path

  1. An attacker provides a direct internal URL or a public URL under the attacker’s control.
  2. The Agent runs scripts/thread.sh with the supplied URL.
  3. The script invokes curl -L from the Agent’s network context.
  4. The request reaches the selected internal destination directly or through an HTTP redirect.
  5. The response is loaded into content and parsed into title, description, and body variables.
  6. Parsed values and observable execution behavior may expose information about the internal endpoint.

Impact Assessment

The vulnerability may enable:

  • Internal HTTP requests using the Agent host’s network reachability.
  • Scanning or probing of internal web services.
  • Access to local administrative interfaces lacking ...[truncated 280 chars]
Remediation
View remediation

Remediation Suggestions

  • Use a strict URL parser and allow only required schemes and ports.
  • Resolve hostnames and reject all non-public IPv4 and IPv6 destinations.
  • Revalidate every redirect target or remove -L.
  • Prevent DNS rebinding by binding the connection to the validated resolution result.
  • Block access to loopback, RFC1918, link-local, and cloud metadata networks through process-level or container-level egress controls.
  • Set an explicit maximum response size and retain the existing timeout.
  • Consider routing public article retrieval through a dedicated fetch service with enforced destination policies.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hook.sh:18
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery in Hook Generation

Content
View full analysis

Vulnerability Details

File Location: scripts/hook.sh:18-23
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: Medium

Vulnerable Code:

bash
if echo "$input" | grep -qE '^https?://'; then
  echo "Fetching article: $input" >&2
  content=$(curl --silent --max-time 20 -L \
    -H "User-Agent: Mozilla/5.0" \
    "$input" 2>&1)

Technical Analysis

The script forwards a user-controlled URL to curl after only checking its scheme prefix. It performs no destination authorization and automatically follows redirects through -L.

This behavior allows requests to addresses beyond the public article sources needed by the Skill, including loopback interfaces, private networks, link-local services, and potentially cloud metadata endpoints. A public URL can also redirect to one of these prohibited destinations.

The static pre-scan’s sensitive-network-transmission warning does not correspond to intentional credential collection in this file. No environment variables, local credentials, or arbitrary local files are attached to the request. The confirmed risk is unrestricted network destination selection.

Attack Path

  1. An attacker submits an internal URL or an attacker-controlled URL that redirects internally.
  2. The Agent invokes scripts/hook.sh.
  3. curl -L makes the request with the Agent host’s network privileges.
  4. The response is stored and parsed for title, description, and body content.
  5. The title-derived topic is reflected in generated hook output, potentially exposing suitably formatted internal response data.
  6. Timing and output differences may also reveal whether an internal endpoint is reachable.

Impact Assessment

Exploitation may provide:

  • Access to HTTP services reachable only from the Agent host.
  • Internal host or service probing.
  • Requests to local administrative services.
  • Potential retrieval of cloud metadata if the runtime and cl ...[truncated 228 chars]
Remediation
View remediation

Remediation Suggestions

  • Restrict fetching to validated public HTTP or HTTPS destinations, preferably HTTPS only.
  • Reject URLs containing credentials or nonstandard ports unless explicitly required.
  • Resolve and classify all destination addresses before connecting, including every IPv6 result.
  • Reject loopback, private, link-local, multicast, unspecified, and reserved destinations.
  • Disable redirects or independently validate each redirect target.
  • Enforce network-level egress restrictions so the script cannot reach internal or metadata networks even if application validation fails.
  • Add a response-size limit and explicit fetch error handling.
  • If feasible, use an allowlist of trusted article domains or a hardened content-fetching proxy.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a general social-post generator, but the documented behavior includes fetching arbitrary URLs with curl/web access that is not clearly declared as a permissioned capability. This mismatch is dangerous because it can hide network-reaching behavior behind an innocuous content-generation description, enabling SSRF-like internal URL access, unexpected data exfiltration, or trust-boundary violations when users supply attacker-controlled URLs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares shell-capable behavior and a required binary (curl) but provides no explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where a consumer may invoke a skill with broader execution capability than expected, increasing the risk of unintended command execution or network use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script will automatically send any user-supplied URL to a remote server via curl without any warning, confirmation, or indication that external network access will occur. In a skill that may be used on private drafts, internal links, or sensitive URLs, this can leak user intent, internal hostnames, and metadata to third parties, and it also enables requests to arbitrary destinations if the input is attacker-controlled.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill should take a blog post URL or text and generate social media posts from it. However, after fetching or reading the input, the script outputs mostly fixed template text such as generic 'what actually works' and 'Stop overthinking' lines, with minimal use of the source content beyond the title or description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The header comment states 'Create a Twitter thread from article' and the usage suggests the input drives the generated thread. In practice, the code uses the input only superficially and fills the thread with predetermined slogans and framework text, which contradicts the documented intent of article-based generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script automatically performs network requests to user-supplied URLs without warning that the target URL and requester metadata will be transmitted to external systems. In a skill intended for repurposing content, this can expose private or internal URLs, trigger unintended outbound requests, and create SSRF-like risk if the input can reference sensitive internal resources.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.