Back to skill

Security audit

style-extractor

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its URL mode can fetch arbitrary web pages and linked CSS without clear network-safety limits.

Use this skill only with trusted public URLs or sandboxed projects. Avoid internal services, localhost, cloud metadata addresses, admin panels, and repositories containing secrets unless you have isolated the environment and reviewed the generated files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:99
Finding

Unrestricted URL Retrieval Enables Server-Side Request Forgery

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 99 and 119–120
Vulnerability Type: Server-Side Request Forgery (SSRF) through insufficient URL validation
Risk Level: Medium

Vulnerable Code

markdown
| URL | starts with `http://` or `https://` | [URL Extraction](#url-extraction) |
markdown
1. **Fetch the page:** Use WebFetch to retrieve the HTML content of the target URL
2. **Fetch CSS:** Use WebFetch on any linked CSS file URLs found in the HTML

Technical Analysis

The Skill determines whether input is a URL solely by checking for an http:// or https:// prefix. It then instructs the Agent to retrieve the supplied URL and automatically retrieve stylesheet URLs discovered in the response.

This behavior is necessary for the declared URL-based style-extraction functionality, but its scope is broader than the minimum privilege required. The instructions do not require validation of:

  • Loopback, private, link-local, multicast, or reserved IP addresses
  • Cloud instance metadata endpoints
  • DNS resolution results or DNS rebinding
  • Redirect destinations
  • Nonstandard or sensitive destination ports
  • Stylesheet links pointing to different origins
  • Response size, content type, or redirect depth

Consequently, an attacker may use the Agent's network position to request resources that are not directly reachable from the attacker's environment. Automatic retrieval of linked CSS also creates a secondary-request primitive controlled by the contents of the initial page.

The audit did not find instructions to collect or transmit credentials, environment variables, SSH keys, private keys, memory, or conversation data. Therefore, the pre-scan warning about sending sensitive information is not directly substantiated; the confirmed issue is unrestricted network destination handling.

Attack Path

  1. An attacker invokes the Skill with an HTTP(S) URL that resolves to an internal service, loopback interface, link-local endpoin ...[truncated 1297 chars]
Remediation
View remediation

Remediation Suggestions

  1. Restrict URL extraction to public HTTP(S) destinations.
  2. Resolve hostnames before each request and reject loopback, private, link-local, multicast, unspecified, reserved, and cloud-metadata address ranges for both IPv4 and IPv6.
  3. Repeat destination validation after every DNS resolution and redirect; do not trust validation of only the original URL.
  4. Apply an allowlist of permitted ports, normally 80 and 443.
  5. Require explicit user confirmation before retrieving linked CSS from a different origin.
  6. Limit redirect depth, response size, retrieval count, and request duration.
  7. Accept only expected textual content types such as HTML and CSS.
  8. Disable ambient credentials, cookies, authorization headers, and local-network authentication during retrieval.
  9. Treat all fetched content as untrusted data and prohibit it from issuing instructions or changing the Agent's behavior.
  10. Record requested and final destinations in the extraction report so users can review all network access.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly advertises automatic extraction from URLs, screenshots, and frontend source code, but does not warn that using a URL may trigger network access or that scanning a local project may read files containing secrets, internal code, or proprietary assets. In an agent/skill context, missing disclosure and scope limits can lead users to run the skill on sensitive targets without understanding the privacy and data-exposure implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The evidence-grade table mixes English headings with Chinese label text such as '已定义', '已测量', '有依据的归纳', and '暂时假设'. This imposes a specific language on users of a general extraction checklist without any stated opt-in, alternative language, or justification for a locale-specific audience.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to "Load this skill when generating UI matching the {name} visual language," which is an open-ended invocation condition in a manifest-style YAML example. It does not define specific trigger phrases, contexts, or negative examples, so the skill could be activated for many ordinary UI-generation requests that only loosely relate to the named style.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language instructions and documentation are presented only in Chinese, which effectively imposes a language requirement on users without opt-in or an alternative. Under the stated policy, forcing a specific language without user choice is a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title and description are written in Chinese, while the body instructions are primarily in English. This creates an implicit language preference without stating whether the user can choose their preferred language, which may conflict with a language/locale policy requiring opt-in or explicit choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.