T09 · Insecure Skill Coding Practices
- Location
scripts/sudoku_fetcher.py:76- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The Sudoku skill is mostly purpose-aligned, but it includes a helper script that can fetch arbitrary web URLs, which is broader than the stated sudokuonline.io use.
Install only if you are comfortable with a Sudoku helper that writes puzzle and render files into your workspace and contacts external Sudoku/SudokuPad-related services. In restricted environments, avoid invoking sudoku_fetcher.py with arbitrary URLs and prefer the documented sudoku.py preset commands.
scripts/sudoku_fetcher.py:76Unrestricted URL Fetching Enables Server-Side Request Forgery
SKILL.md:32Runtime Dependencies Are Installed Without Version or Integrity Pinning
The skill advertises and documents capabilities that read/write workspace files and contact an external network service, but no permissions are explicitly declared. This creates a transparency and consent problem: users or hosting systems may not realize the skill can exfiltrate data via network access or persist data locally, which weakens sandboxing and policy enforcement.
The documentation does not clearly warn that using the skill will contact an external service and write puzzle data into the workspace. While expected for this type of tool, the lack of an upfront notice can lead to uninformed use in restricted or privacy-sensitive environments.
No suspicious patterns detected.