T09 · Insecure Skill Coding Practices
Error
- Location
src/api.js:329- Finding
Arbitrary URL Fetch Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a coherent Marktplaats search tool, but it exposes an overbroad detail fetcher that can request arbitrary URLs and documents an ambiguous npx command that may run an unrelated package.
Review this before installing. Use it only in environments where arbitrary outbound HTTP requests are acceptable, avoid passing untrusted values to --details or getListingDetails, and prefer the documented local/global install path over the README npx command unless the package name and version are explicitly pinned.
src/api.js:329Arbitrary URL Fetch Enables Server-Side Request Forgery
README.md:8Unpinned npx Instruction May Execute an Unrelated Registry Package
No suspicious patterns detected.