T09 · Insecure Skill Coding Practices
- Location
SKILL.md:39- Finding
Unrestricted Callback URL May Expose Sensitive Database Information
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39–45
Vulnerability Type: User-controlled outbound callback destination
Risk Level: HighVulnerable Code
markdown ## Input Definition | Parameter | Type | Required | Description | |---|---|---|---| | input | string | Yes | Input data or instructions processed by the SQL assistant | | options | object | No | Additional configuration, such as mode or format preferences | | callback_url | string | No | Callback URL notified after asynchronous processing |The underlying declaration defines
callback_urlas an unrestricted string and does not specify any destination or payload security controls.Technical Analysis
The Skill accepts a user-controlled callback URL for asynchronous result delivery. No requirements are provided for HTTPS enforcement, trusted-origin allowlisting, redirect handling, DNS rebinding protection, private-address rejection, callback authentication, or outbound payload filtering.
SQL-assistance inputs and outputs can contain sensitive material, including table schemas, column names, SQL statements, business identifiers, query plans, and potentially query results. Sending such output to an arbitrary callback destination can disclose this information to an attacker-controlled server.
The callback can also create a server-side request forgery condition if the execution environment honors the documented parameter without additional validation. An attacker could supply a loopback, private-network, link-local, or cloud metadata address and cause the Agent to issue a request to a service that is not directly accessible to the attacker.
The risk is amplified by the Skill's broad
read,exec, andwritetool declarations and its generic API-integration capability. However, the audited file does not contain a concrete command that directly reads credentials or transmits an API key.Attack Path
- An attacker or un ...[truncated 1298 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove callback functionality if asynchronous outbound delivery is not essential to the declared SQL-assistance functionality.
- Require explicit, informed user confirmation before transmitting SQL, schemas, query plans, or database results to any external endpoint.
- Restrict destinations to a configured allowlist of trusted HTTPS origins. Do not accept arbitrary URLs directly from task input.
- Reject loopback, private, link-local, multicast, and reserved IP ranges after DNS resolution, including IPv4 and IPv6 representations.
- Revalidate the destination after every redirect and either disable redirects or restrict them to the same approved origin.
- Protect against DNS rebinding by resolving and validating addresses at connection time.
- Define a minimal callback schema and exclude raw input, credentials, connection strings, complete schemas, and query results by default.
- Redact secrets and sensitive fields before transmission and impose payload-size limits.
- Authenticate callback destinations and cryptographically sign callback payloads so recipients can verify their origin and integrity.
- Apply strict connection and response timeouts, response-size limits, retry limits, and outbound network controls.
- Record callback destination, approval, payload classification, and delivery result in security audit logs without logging secrets.
- Remove or narrowly scope the declared
exec,read, andwritetools unless a specific operation requires them.
