T09 · Insecure Skill Coding Practices
- Location
scripts/bad-website-hunter.js:90- Finding
Unvalidated Remote URLs Enable Server-Side Request Forgery
- Content
View full analysis
{ const u = new URL(url); https.get({ hostname: u.hostname, path: u.pathname + u.search, headers: { 'User-Agent': 'Mozilla/5.0', ...headers } }, res => { let d = ''; res.on('data', c => d += c); res.on('end', () => resolve({ status: res.statusCode, data: d, headers: res.headers })); }).on('error', reject); }); } ``` ```js return (json.web?.results || []).map(r => ({ name: r.title, url: r.url, description: r.description })); ``` ```js async function scoreWebsite(url) { const score = { ssl: 0, mobile: 0, speed: 0, design: 0, content: 0, total: 0, issues: [] }; try { const start = Date.now(); const res = await httpGet(url); ``` ```js async function extractEmail(url) { try { // Try DeepCrawl first if available if (DEEPCRAWL_KEY) { const dcUrl = `https://api.deepcrawl.dev/read?url=${encodeURIComponent(url)}`; const res = await httpGet(dcUrl, { 'Authorization': 'Bearer ' + DEEPCRAWL_KEY }); const emailMatch = res.data.match(/[\w.+-]+@[\w-]+\.[\w.]+/g); if (emailMatch) return emailMatch[0]; // Try /contact page const contactUrl = url.replace(/\/$/, '') + '/contact'; const res2 = await httpGet(`https://api.deepcrawl.dev/read?url=${encodeURIComponent(contactUrl)}`, { 'Authorization': 'Bearer ' + DEEPCRAWL_KEY }); const emailMatch2 = res2.data.match(/[\w.+-]+@[\w-]+\.[\w.]+/g); if (emailMatch2) return emailMatch2[0]; } // Fallback: direct scrape const res = await httpGet(url); ``` ```js for (const biz of businesses) { results.scanned++; const score = await scoreWebsite(biz.url); ``` ### Technical Analysis ...[truncated 2120 chars]- Remediation
View remediation
