T09 · Insecure Skill Coding Practices
- Location
pipeline_full.py:186- Finding
Unvalidated and Unbounded Download of Remotely Supplied Media
- Content
View full analysis
= 720 and "mp4" in f.get("file_type", "")), files[0]["link"] if files else None ) if not url: continue clip_path = os.path.join(output_dir, f"clip_{len(collected):02d}.mp4") print(f" Downloading {len(collected)+1}/{needed}: {video.get('duration','?')}s by {video.get('user',{}).get('name','?')}") # Stream download dl = requests.get(url, stream=True, timeout=90) dl.raise_for_status() with open(clip_path, "wb") as f: for chunk in dl.iter_content(chunk_size=8192): f.write(chunk) ``` The documented implementation in `SKILL.md` contains the same behavior: ```python path = os.path.join(output_dir, f"clip_{len(collected):02d}.mp4") with open(path, "wb") as f: for chunk in requests.get(url, stream=True, timeout=60).iter_content(8192): f.write(chunk) ``` ### Technical Analysis The download URL is taken directly from the Pexels API response and passed to `requests.get()` without validating its scheme, destination hostname, redirects, declared content type, or expected file size. Python Requests follows redirects by default. The downloaded content is stored with an `.mp4` extension regardless of its actual type and is subsequently opened by MoviePy and FFmpeg. Consequently, the code crosses two trust boundaries: it permits a remote response to select a network destination, and then supplies untrusted bytes to complex native media parsers. The initial Pexels API request is necessary for the declared stock-footage functionality. However, unrestricted destination selection and unbounded downloads exceed the minimum network a ...[truncated 1471 chars]- Remediation
View remediation
MAX_CLIP_BYTES: raise ValueError("Media exceeds maximum permitted size") f.write(chunk) ``` ]]>
