T09 · Insecure Skill Coding Practices
- Location
scripts/whatslink_query.py:45- Finding
Potentially Sensitive Target URLs Can Be Disclosed to Arbitrary Network Endpoints
- Content
View full analysis
Vulnerability Details
File Location:
scripts/whatslink_query.py:45-51, 160-169
Vulnerability Type: Unrestricted transmission of user-supplied URLs to configurable external endpoints
Risk Level: MediumComplete Code Snippet
python def fetch_metadata(endpoint: str, target_url: str, timeout: float, user_agent: str | None) -> dict[str, Any]: query_url = build_query_url(endpoint, target_url) headers = {"User-Agent": user_agent or DEFAULT_UA, "Accept": "application/json"} request = Request(query_url, headers=headers) try: with urlopen(request, timeout=timeout) as response:python parser.add_argument("url", help="要检查的公开 URL。不要传入私密、带 token 或内网链接。") parser.add_argument("--json", action="store_true", help="输出 WhatsLink 原始 JSON 响应。") parser.add_argument("--no-screenshots", action="store_true", help="在人类可读摘要中隐藏截图 URL。") parser.add_argument("--max-screenshots", type=non_negative_int, default=None, help="摘要中最多展示的截图 URL 数量(默认:全部)。传 0 表示不列出。") parser.add_argument("--timeout", type=positive_timeout, default=20.0, help="请求超时时间,单位秒(默认:20)。") parser.add_argument("--endpoint", default=DEFAULT_ENDPOINT, help=f"API endpoint (default: {DEFAULT_ENDPOINT}).") parser.add_argument("--user-agent", default=None, help="可选的自定义 User-Agent。") return parser.parse_args(argv) def main(argv: list[str] | None = None) -> int: args = parse_args(argv or sys.argv[1:]) try: data = fetch_metadata(args.endpoint, args.url, args.timeout, args.user_agent)Technical Analysis
The script embeds the complete user-supplied target URL in the
urlquery parameter of an outbound request. This transmission is necessary for the declared metadata lookup when the target is a public, non-sensitive link. However, the restrictions documented inSKILL.mdand the CLI help are advisory only.The code does not reject URLs containing user information, signed query parameters, API keys, session identifiers, or other secrets. It also does no ...[truncated 1793 chars]
- Remediation
View remediation
Remediation Suggestions
- Restrict the default network destination to an explicit allowlist containing only the documented WhatsLink HTTPS endpoint.
- Require a conspicuous opt-in flag for alternative endpoints, and reject non-HTTPS endpoints unless an additional testing-only override is supplied.
- Validate target URLs before transmission:
- Permit only
httpandhttpsschemes. - Reject embedded usernames or passwords.
- Reject localhost, loopback, link-local, private-network, and internal hostnames.
- Reject or require explicit confirmation for sensitive query keys such as
token,access_token,api_key,key,signature,sig,session, andauth.
- Permit only
- Disable redirects or validate every redirect destination against the same HTTPS allowlist before forwarding the request.
- Warn the user immediately before external transmission and identify the exact destination service.
- Avoid printing complete sensitive target URLs in output or error paths; redact credentials and sensitive query values.
- Keep the existing documentation warnings, but enforce them in code rather than relying solely on caller behavior.
