T09 · Insecure Skill Coding Practices
- Location
scripts/generate.sh:22- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery in Post Generation
- Content
View full analysis
&2 content=$(curl --silent --max-time 20 -L \ -H "User-Agent: Mozilla/5.0" \ "$input" 2>&1) ``` ### Technical Analysis The script passes a user-controlled HTTP or HTTPS URL directly to `curl`. Although the URL is quoted, which prevents shell command injection, its destination is not validated before the network request is made. The `-L` option follows redirects, but neither the original URL nor redirect destinations are checked for loopback, private, link-local, reserved, or cloud metadata addresses. An attacker who can control the input can therefore cause the runtime environment to issue HTTP GET requests to services reachable from the Agent's network context. Fetching public articles is necessary for the declared functionality, but unrestricted access to arbitrary network destinations exceeds the minimum privilege required. ### Attack Path 1. An attacker supplies a URL such as a loopback address, private-network service, cloud metadata address, or attacker-controlled public URL that redirects to one. 2. The script accepts the value because it starts with `http://` or `https://`. 3. `curl -L` connects to the destination and follows redirects without validating the resolved addresses. 4. The internal response is stored in `content` and parsed as article content. 5. Depending on the response format, parts of the response may influence generated output. Even without response disclosure, the request can act as a blind SSRF probe against internal HTTP services. ### Impact Assessment The vulnerability grants access to the network privileges of the environment running the Skill. Potential consequences include: - Blind probing of localhost and internal HTTP services. - Requests ...[truncated 450 chars]- Remediation
View remediation
