T09 · Insecure Skill Coding Practices
- Location
SKILL.md:1698- Finding
Unrestricted Webhook Destination Enables SSRF and Alert Metadata Disclosure
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a non-executable observability guide with expected telemetry and alerting examples, but copied code should be configured to avoid sending sensitive business data to third parties.
Before copying the examples into production, decide what telemetry may leave your environment. Redact or hash customer, transaction, escrow, credential, and internal topology identifiers; use allowlisted HTTPS webhook destinations; and document retention and access controls for GreenHelix, Slack, and any observability backend.
SKILL.md:1698Unrestricted Webhook Destination Enables SSRF and Alert Metadata Disclosure
SKILL.md:944Unrestricted Metric Dimensions May Export Sensitive Data to an External Telemetry Service
The guide encourages sending traces, metrics, billing amounts, escrow identifiers, transaction IDs, and other operational/business metadata to GreenHelix and external observability backends without clearly warning that this telemetry may contain sensitive information. In practice, users often copy production examples verbatim, which can result in unintentional exposure of internal topology, financial data, and customer-linked identifiers to third-party services.
The webhook and Slack alerting examples transmit alert contents, metric values, agent IDs, and dimensions to third-party endpoints without a prominent warning about data disclosure risks. Because alert payloads often include operational state and can be expanded by users to include trace or transaction context, this pattern can leak sensitive fleet and business information outside the primary environment.
At L1928 the inline comment says the code will "register webhook with GreenHelix for event-driven alerts," which implies creation of a webhook subscription. The actual implementation at L1931-L1942 only calls submit_metrics to emit an alerts.fired metric and never invokes register_webhook or any equivalent registration behavior.
No suspicious patterns detected.