Back to skill

Security audit

Web fetch markdown of page

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it can send full user-supplied URLs to jina.ai without clear limits for private or token-bearing links.

Install only if you are comfortable with public web URLs being sent through jina.ai for markdown conversion. Do not use it for password reset links, signed download URLs, internal hosts, private documents, authenticated pages, or links with secrets or access tokens in the path or query string unless the skill is updated to block or confirm those cases.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:21
Finding

Unrestricted Disclosure of Sensitive User-Supplied URLs to a Third-Party Service

Content
View full analysis
` 3. Use `web_fetch` tool with the constructed URL 4. Return the markdown content to user ``` ### Technical Analysis The Skill instructs the Agent to place an unmodified user-supplied URL into a request sent to `r.jina.ai`. This third-party request is necessary for the Skill's declared proxy-based Markdown extraction functionality and is not covert network exfiltration. However, the instructions do not validate the URL or warn users that the entire URL will be disclosed to an external service. URLs can contain sensitive information, including: - Signed cloud-storage access parameters - Password-reset or account-verification tokens - API keys and session identifiers in query parameters - HTTP user-information credentials - Private document identifiers and internal resource names - Tracking or other confidential query parameters Consequently, invoking the Skill with a sensitive URL sends that information to jina.ai and potentially to its network, application, and logging infrastructure. The Skill does not restrict processing to public resources, remove sensitive components, or obtain explicit consent before third-party disclosure. ### Attack Path 1. An attacker supplies or persuades a user to process a token-bearing URL, such as a signed document URL, password-reset link, or temporary cloud-storage link. 2. The user asks the Agent to fetch or condense the URL using this Skill. 3. Following `SKILL.md`, the Agent appends the complete original URL to `https://r.jina.ai/`. 4. The Agent sends the resulting request through `web_fetch`. 5. jina.ai receives the complete sensitive URL, including embedded credentia ...[truncated 969 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to prepend URLs to r.jina.ai, which sends the target URL to a third-party proxy, but it does not disclose this data flow or its privacy implications. This is especially risky if users provide private links, signed URLs, internal endpoints, or sensitive query parameters, because those may be transmitted to and logged by an external service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation language is broad enough to match ordinary web-fetch requests, not just cases where a user specifically wants third-party markdown reduction via jina.ai. This can cause the skill to be invoked unexpectedly and route requests through an external proxy, increasing privacy and data-handling risk beyond user expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'When to Use' guidance lacks boundaries, so an agent may apply the skill in many ambiguous situations involving long web content. In this context, overbroad invocation is dangerous because the skill forwards the requested URL to a third-party service, potentially exposing browsing targets or sensitive query strings without clear user consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.