T09 · Insecure Skill Coding Practices
- Location
references/openapi.yaml:12- Finding
Alternate Mock Server May Receive Financial and Wallet Metadata
- Content
View full analysis
Vulnerability Details
File Location:
references/openapi.yaml:12-17
Related Instruction:SKILL.md:28-36
Vulnerability Type: Unnecessary third-party network destination in API configuration
Risk Level: MediumVulnerable Code
yaml servers: - description: Sushi API url: https://api.sushi.com # Added by API Auto Mocking Plugin - description: SwaggerHub API Auto Mocking url: https://virtserver.swaggerhub.com/sushi-labs/sushi/7.0.0The Skill instructs agents to select behavior dynamically from this schema:
markdown Agents must **always rely on the schema contents** rather than hardcoded assumptions. ## How To Use 1. Load `references/openapi.yaml` 2. Discover available endpoints, parameters, and response shapes dynamically 3. Select the appropriate endpoint based on user intent and schema tagsTechnical Analysis
The OpenAPI document lists a SwaggerHub mock server as an alternative to the intended production server,
https://api.sushi.com. Schema-driven clients can select any server declared by the specification. The Skill does not expressly forbid use of the mock server or require an allowlist containing only the production origin.Swap requests can contain wallet addresses in
senderandrecipient, token addresses, transaction amounts, referrer identity, fee receiver, and route preferences. Sending these parameters to the mock service would expose financial metadata and trading intent to an additional third party. The mock server is not required to provide the Skill's declared production SushiSwap integration and therefore exceeds the minimum network scope necessary for that functionality.This finding does not indicate access to private keys, seed phrases, signing capabilities, local files, or elevated system privileges. The exposed scope is limited to request metadata deliberately included in API calls, but that data may still identify wallets ...[truncated 1076 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the SwaggerHub mock server from the OpenAPI document distributed with the production Skill.
- Retain only
https://api.sushi.comas an authorized server. - Add an explicit instruction requiring agents and clients to reject all schema server URLs except the allowlisted production origin.
- If a mock server is required for development, place it in a separate development-only schema that is not shipped with the Skill.
- Validate the final request origin immediately before transmission.
- Avoid logging complete query strings containing wallet addresses, amounts, fee receivers, or other financial metadata.
