Back to skill

Security audit

Link Checker

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent link-checking skill, but it can make unrestricted network requests from the user’s environment and does not clearly scope or warn about that risk.

Install only if you are comfortable with the skill making outbound HEAD requests to every discovered link from your machine or CI environment. Use it only on trusted site content or inside a network-isolated runner until it adds destination validation, private-address blocking, redirect controls, and a dry-run or allowlist mode.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/check.sh:65
Finding

Unrestricted URL Requests Enable Server-Side Request Forgery and Internal Network Probing

Content
View full analysis
/dev/null) ``` #### `scripts/quick.sh:61-63` ```python result = subprocess.run( ["curl", "-s", "-o", "/dev/null", "-w", "%{http_code}", "--max-time", str(timeout), "-L", "-I", url], capture_output=True, text=True, timeout=timeout + 2 ) ``` #### `scripts/affiliate.sh:70-72` ```python result = subprocess.run( ["curl", "-s", "-o", "/dev/null", "-w", "%{http_code}", "--max-time", str(timeout), "-L", "-I", url], capture_output=True, text=True, timeout=timeout + 2 ) ``` ### Technical Analysis The scripts extract URLs from HTML files supplied through a directory argument or the `SITE_DIR` environment variable and pass those URLs directly to `curl`. They do not validate the resolved destination before making the request. The implementations do not reject: - IPv4 or IPv6 loopback addresses - RFC1918 private-network addresses - Link-local addresses - Cloud instance metadata endpoints - Multicast, reserved, or otherwise non-public addresses - Hostnames that resolve to internal addresses - Public URLs that redirect to internal addresses The `-L` option instructs `curl` to follow redirects automatically. Consequently, validating only the original URL would not be sufficient: an apparently public URL can redirect the request to an internal service. Every redirect destination must be validated before it is contacted. The full checker is especially permissive because `scripts/check.sh` does not explicitly restrict extracted links to HTTP and HTTPS before passing them to `curl`. The two Python implementat ...[truncated 2549 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This second mismatch finding likewise indicates the skill overstates what it audits, claiming internal/external validation, redirect reporting, slow-link detection, and affiliate identification that the implementation does not actually provide. In security and site-health workflows, inaccurate capability claims can suppress additional validation steps and lead operators to trust incomplete results.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This second mismatch finding likewise indicates the skill overstates what it audits, claiming internal/external validation, redirect reporting, slow-link detection, and affiliate identification that the implementation does not actually provide. In security and site-health workflows, inaccurate capability claims can suppress additional validation steps and lead operators to trust incomplete results.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises shell- and file-based behavior but does not declare any explicit tool scope such as permissions or allowed-tools. In agent environments, missing scope boundaries can let the runtime grant broader-than-necessary file access or shell execution, increasing the blast radius if the skill is invoked on untrusted content or modified later.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically sends HTTP requests to every discovered affiliate URL using curl, which discloses those URLs and the runner's IP/user-agent to third-party services without any warning or consent gate. In a CI runner, corporate network, or private pre-publication workflow, this can leak unpublished content relationships, tracking parameters, or internal campaign data to external domains.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The comment states this is a 'Fast broken-link scan only (no slow/redirect/affiliate checks)'. However, the curl invocation uses '-L' at L64, which follows redirects before evaluating the final HTTP status, so the script is in fact handling redirects rather than excluding them entirely. This is a direct contradiction between the documented intent and implemented behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.