T09 · Insecure Skill Coding Practices
- Location
scripts/common.sh:202- Finding
Weak Luma Domain Validation Allows Automatic Submission to Phishing Hosts
- Content
View full analysis
/dev/null || echo "[]" } ``` Discovery does not perform compensating URL validation: ```bash # Set rsvp_status to "ok" for all events (skip slow per-URL HEAD validation) # Dead links are caught at registration time when the page fails to load log_info "Skipping URL validation (handled at registration time)..." ``` ### Technical Analysis The code treats a URL as a trusted Luma URL whenever its complete string contains `lu.ma` or `luma.com`. This does not validate the parsed hostname. Attacker-controlled URLs such as the following pass the test: ```text https://lu.ma.attacker.example/register https://attacker.example/path/luma.com https://fake-luma.com/register ``` The accepted URL is subsequently opened by `cli_register_event`. The registration agent receives the user's name, email, and saved custom answers and is instructed to fill and submit the displayed form. Consequently, this validation defect crosses a sensitive trust boundary. The README states that RSV ...[truncated 1384 chars]- Remediation
View remediation
