T09 · Insecure Skill Coding Practices
- Location
SKILL.md:21- Finding
Unrestricted Disclosure of Sensitive User-Supplied URLs to a Third-Party Service
- Content
View full analysis
` 3. Use `web_fetch` tool with the constructed URL 4. Return the markdown content to user ``` ### Technical Analysis The Skill instructs the Agent to place an unmodified user-supplied URL into a request sent to `r.jina.ai`. This third-party request is necessary for the Skill's declared proxy-based Markdown extraction functionality and is not covert network exfiltration. However, the instructions do not validate the URL or warn users that the entire URL will be disclosed to an external service. URLs can contain sensitive information, including: - Signed cloud-storage access parameters - Password-reset or account-verification tokens - API keys and session identifiers in query parameters - HTTP user-information credentials - Private document identifiers and internal resource names - Tracking or other confidential query parameters Consequently, invoking the Skill with a sensitive URL sends that information to jina.ai and potentially to its network, application, and logging infrastructure. The Skill does not restrict processing to public resources, remove sensitive components, or obtain explicit consent before third-party disclosure. ### Attack Path 1. An attacker supplies or persuades a user to process a token-bearing URL, such as a signed document URL, password-reset link, or temporary cloud-storage link. 2. The user asks the Agent to fetch or condense the URL using this Skill. 3. Following `SKILL.md`, the Agent appends the complete original URL to `https://r.jina.ai/`. 4. The Agent sends the resulting request through `web_fetch`. 5. jina.ai receives the complete sensitive URL, including embedded credentia ...[truncated 969 chars]- Remediation
View remediation
