T09 · Insecure Skill Coding Practices
- Location
scripts/fetch.js:200- Finding
Arbitrary URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
a.startsWith('http')); ``` ### Technical Analysis The fetch command accepts an arbitrary string beginning with `http` and sends a request to it through either the Node.js Fetch API or Chromium. It does not validate the URL protocol using a URL parser, resolve and inspect the destination address, or reject loopback, link-local, private, reserved, and cloud metadata address ranges. The HTTP implementation also uses `redirect: 'follow'`. Consequently, validating only the original URL would remain insufficient because a public endpoint could redirect the request to a protected internal destination. The Playwright fallback is affected independently because `page.goto()` can navigate directly to internal HTTP services. This functionality requires access to user-selected public web pages, but unrestricted access to destinations visible from the Agent host exceeds that requirement. ### Attack Path 1. An attacker causes the Agent to invoke the fetch tool with an internal URL, such as a loopback service, private-network host, or cloud instance metadata endpoint. 2. Alternatively, the attacker provides an apparently public URL that redirects to an internal address. 3. `scripts/fetch.js` accepts the URL because it begins with `http`. 4. The lightweight HTTP tier follows the destination and an ...[truncated 944 chars]- Remediation
View remediation
