T09 · Insecure Skill Coding Practices
- Location
SKILL.md:99- Finding
Unrestricted URL Retrieval Enables Server-Side Request Forgery
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 99 and 119–120
Vulnerability Type: Server-Side Request Forgery (SSRF) through insufficient URL validation
Risk Level: MediumVulnerable Code
markdown | URL | starts with `http://` or `https://` | [URL Extraction](#url-extraction) |markdown 1. **Fetch the page:** Use WebFetch to retrieve the HTML content of the target URL 2. **Fetch CSS:** Use WebFetch on any linked CSS file URLs found in the HTMLTechnical Analysis
The Skill determines whether input is a URL solely by checking for an
http://orhttps://prefix. It then instructs the Agent to retrieve the supplied URL and automatically retrieve stylesheet URLs discovered in the response.This behavior is necessary for the declared URL-based style-extraction functionality, but its scope is broader than the minimum privilege required. The instructions do not require validation of:
- Loopback, private, link-local, multicast, or reserved IP addresses
- Cloud instance metadata endpoints
- DNS resolution results or DNS rebinding
- Redirect destinations
- Nonstandard or sensitive destination ports
- Stylesheet links pointing to different origins
- Response size, content type, or redirect depth
Consequently, an attacker may use the Agent's network position to request resources that are not directly reachable from the attacker's environment. Automatic retrieval of linked CSS also creates a secondary-request primitive controlled by the contents of the initial page.
The audit did not find instructions to collect or transmit credentials, environment variables, SSH keys, private keys, memory, or conversation data. Therefore, the pre-scan warning about sending sensitive information is not directly substantiated; the confirmed issue is unrestricted network destination handling.
Attack Path
- An attacker invokes the Skill with an HTTP(S) URL that resolves to an internal service, loopback interface, link-local endpoin ...[truncated 1297 chars]
- Remediation
View remediation
Remediation Suggestions
- Restrict URL extraction to public HTTP(S) destinations.
- Resolve hostnames before each request and reject loopback, private, link-local, multicast, unspecified, reserved, and cloud-metadata address ranges for both IPv4 and IPv6.
- Repeat destination validation after every DNS resolution and redirect; do not trust validation of only the original URL.
- Apply an allowlist of permitted ports, normally 80 and 443.
- Require explicit user confirmation before retrieving linked CSS from a different origin.
- Limit redirect depth, response size, retrieval count, and request duration.
- Accept only expected textual content types such as HTML and CSS.
- Disable ambient credentials, cookies, authorization headers, and local-network authentication during retrieval.
- Treat all fetched content as untrusted data and prohibit it from issuing instructions or changing the Agent's behavior.
- Record requested and final destinations in the extraction report so users can review all network access.
