T09 · Insecure Skill Coding Practices
- Location
SKILL.md:52- Finding
Unencrypted arXiv API Requests Permit Response Tampering
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:52references/arxiv-guide.md:13
Vulnerability Type: Use of an unencrypted HTTP connection for externally retrieved paper metadata
Risk Level: MediumVulnerable Code in
SKILL.md:52:bash curl -s "http://export.arxiv.org/api/query?id_list=XXXXXXX" -H "User-Agent: Mozilla/5.0"Vulnerable Code in
references/arxiv-guide.md:13:bash curl -s "http://export.arxiv.org/api/query?id_list=XXXXXXX"Technical Analysis
The documented workflow retrieves arXiv metadata and abstracts over plaintext HTTP. HTTP provides neither server authentication nor transport integrity. An attacker with a network position between the agent and the arXiv API—such as a malicious Wi-Fi operator, compromised proxy, or local network attacker—could intercept and modify the Atom response.
The workflow subsequently treats the retrieved title, author information, abstract, and related metadata as trusted input for translation, analysis, and diagram generation. Consequently, a modified response could cause the agent to produce falsified paper summaries or diagrams.
The retrieved response is treated as document content rather than executable code, so the reviewed instructions do not establish direct command execution or privilege escalation from this issue alone.
Attack Path
- A user supplies an arXiv identifier or URL.
- The agent follows the documented fallback procedure and requests the arXiv API endpoint over HTTP.
- A network-positioned attacker intercepts the plaintext request.
- The attacker returns a modified Atom response containing falsified metadata or abstract content.
- The agent translates and analyzes the altered content.
- The resulting Markdown report and HTML diagram present attacker-controlled information as though it came from arXiv.
Impact Assessment
The vulnerability primarily compromises the integrity and authe ...[truncated 419 chars]
- Remediation
View remediation
Remediation Suggestions
-
Replace every plaintext API URL with the HTTPS endpoint:
bash curl --fail --silent --show-error \ --proto '=https' \ --max-redirs 0 \ "https://export.arxiv.org/api/query?id_list=XXXXXXX" \ -H "User-Agent: Mozilla/5.0" -
Update both
SKILL.mdandreferences/arxiv-guide.mdso users and agents are not directed to the insecure endpoint. -
Fail closed on TLS certificate validation errors. Do not use options such as
--insecureor-k. -
If redirects must be supported, restrict them to HTTPS destinations and an explicit allowlist of expected arXiv hosts.
-
Validate the returned response format and ensure the requested arXiv identifier matches the identifier in the API response.
-
Where output integrity is important, corroborate critical metadata through a second HTTPS-protected source, such as the arXiv abstract page or Crossref.
-
