T09 · Insecure Skill Coding Practices
- Location
collect.js:30- Finding
Unrestricted Browser Navigation Enables Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
{ const requestUrl = new URL(route.request().url()); if (!(await isAllowedNetworkDestination(requestUrl))) { return route.abort(); } return route.continue(); }); ``` 5. Validate every redirect destination. Browser-level request interception should remain active for the entire context so that redirects and subresources receive the same checks. 6. If the intended use is limited to approved storefronts, enforce an explicit hostname allowlist. 7. Apply the same centralized URL validation helper to every collector variant rather than maintaining separate implementations. ]]>
