T09 · Insecure Skill Coding Practices
- Location
fetch.sh:6- Finding
Unvalidated URLs Are Disclosed to External Content Services in the Shell Implementation
- Content
View full analysis
[method]" echo "Methods: jina (default), markdown, defuddle" exit 1 fi ENCODED_URL="$URL" echo "=== Attempting to fetch: $URL ===" >&2 echo "Method: $METHOD" >&2 case "$METHOD" in jina) echo "--- Using r.jina.ai ---" >&2 curl -s "https://r.jina.ai/$ENCODED_URL" ;; markdown) echo "--- Using markdown.new ---" >&2 curl -s "https://markdown.new/$ENCODED_URL" ;; defuddle) echo "--- Using defuddle.md ---" >&2 curl -s "https://defuddle.md/$ENCODED_URL" ;; all) echo "=== Trying all methods ===" >&2 echo "--- r.jina.ai ---" >&2 curl -s "https://r.jina.ai/$ENCODED_URL" echo -e "\n--- markdown.new ---" >&2 curl -s "https://markdown.new/$ENCODED_URL" echo -e "\n--- defuddle.md ---" >&2 curl -s "https://defuddle.md/$ENCODED_URL" ;; ``` ### Technical Analysis The script embeds the complete user-supplied URL into a request sent to `r.jina.ai`, `markdown.new`, or `defuddle.md`. It does not validate the URL scheme, reject embedded credentials, remove sensitive query parameters, or obtain explicit confirmation before disclosing the value. URLs commonly contain signed query strings, password-reset tokens, API credentials, session identifiers, private document identifiers, and internal hostnames. The selected external provider can observe and potentially log the complete target URL. The `all` method expands the disclosure to all three providers. The quoted shell variable prevents ordinary shell command injection through the URL. The confirmed issue is third-party data disclosure rather than arbitrary local command execution. ### Attack Path ...[truncated 825 chars]- Remediation
View remediation
