Intent-Code Divergence
Medium
- Confidence
- 98% confidence
- Finding
- The skill explicitly claims SSRF protection, but the validator only rejects a few localhost-style hostnames and allows many dangerous cases such as private RFC1918 ranges, link-local addresses, IPv6 loopback, DNS rebinding targets, and internal hostnames. In this skill context, the API endpoint is taken from an environment variable and then contacted with local file contents, so a misconfigured or attacker-influenced URL could cause sensitive PDF data or credentials to be sent to unintended internal or malicious destinations.
