T09 · Insecure Skill Coding Practices
- Location
scripts/api.sh:42- Finding
Bearer Token Disclosure Through an Unvalidated API Origin
- Content
View full analysis
&2 exit 64 fi base_url=${HOF_API_URL%/} auth_config='' response_file='' token=${HOF_TOKEN:-} if [[ -z $token && -n ${HOF_TOKEN_FILE:-} && -f $HOF_TOKEN_FILE ]]; then token=$(<"$HOF_TOKEN_FILE") fi if [[ $method != AUTH && -n $token ]]; then auth_config=$(mktemp) chmod 600 "$auth_config" printf 'header = "Authorization: Bearer %s"\n' "$token" >"$auth_config" curl_args+=(--config "$auth_config") fi ``` The authenticated request is subsequently sent to the configured URL: ```bash curl "${curl_args[@]}" "${request_args[@]}" "${base_url}${path}" ``` ### Technical Analysis The script verifies only that `HOF_API_URL` is nonempty. It does not parse the URL, require HTTPS, restrict the destination to an approved Hall Of Fame API host, or verify that the selected origin is trusted before attaching the bearer token. For every non-`AUTH` request, the helper adds the account's bearer token and sends the request to the origin supplied through `HOF_API_URL`. If runtime configuration, environment setup, or agent-generated command parameters cause this variable to point to an attacker-controlled endpoint, the endpoint receives a valid account credential. An `http://` endpoint could also expose the token to network interception. ### Attack Path 1. An attacker influences the runtime environment, deployment configuration, or instructions used to set `HOF_API_URL`. 2. `HOF_API_URL` is set to an attacker-controlled origin, such as `https://attacker.example/api`, or to an unencrypted HTTP endpoint. 3. A normal authenticated operation is invoked, such as: ```bash scripts/api.sh GET /auth/me ``` 4. The helper loads the token from `HOF_TOKEN` or `HOF_TOKEN ...[truncated 880 chars]- Remediation
View remediation
