T09 · Insecure Skill Coding Practices
- Location
scripts/url-to-summary.sh:5- Finding
Unrestricted URL Fetching Enables SSRF and Local File Disclosure
- Content
View full analysis
" echo "Example: $0 https://example.com/article" exit 1 fi mkdir -p "$OUTPUT_DIR" TIMESTAMP=$(date +%s) TMP_CONTENT=$(mktemp) TMP_CLEAN=$(mktemp) TMP_SENTENCES=$(mktemp) trap "rm -f $TMP_CONTENT $TMP_CLEAN $TMP_SENTENCES" EXIT echo "Fetching: $URL" >&2 curl -sL --max-time 30 -A "Mozilla/5.0 (compatible; ContentSummarizer/1.0)" "$URL" > "$TMP_CONTENT" 2>/dev/null ``` `scripts/key-points.sh:19-21`: ```bash if [[ "$INPUT" =~ ^https?:// ]]; then CONTENT=$(curl -sL --max-time 30 -A "content-summarizer/1.0" "$INPUT" || true) ``` ### Technical Analysis Both network-fetching paths accept attacker-controlled destinations and invoke `curl` with redirect following enabled through `-L`. The implementation does not: - Restrict destinations to approved external hosts. - Reject loopback, link-local, private, multicast, or reserved IP ranges. - Resolve hostnames and validate all returned addresses. - Revalidate the destination after every redirect. - Limit `url-to-summary.sh` to HTTP or HTTPS URI schemes. In `url-to-summary.sh`, an arbitrary string is passed directly to `curl`. Consequently, any URI scheme supported by the installed curl build may be accepted. This can include `file://`, allowing files readable by the Skill process to be copied into the generated summary workflow. The minimum-length checks limit which files produce successful output but do not prevent the underlying read. Although `key-points.sh` initially requires an HTTP or HTTPS-looking input, `curl -L` can follow an attacker-controlled redirect to an int ...[truncated 1949 chars]- Remediation
View remediation
