T09 · Insecure Skill Coding Practices
- Location
skill.py:635- Finding
Configurable External Endpoints Can Bypass Remote Upload and Consent Controls
- Content
View full analysis
Vulnerability Details
File Location:
skill.py:482-495,skill.py:498-537,skill.py:550-567, andskill.py:635-660
Vulnerability Type: Improper trust classification of configurable network endpoints
Risk Level: MediumVulnerable Code
python class VLClient: """VL model client""" def __init__(self, endpoint: str, model: str, api_key: str = "", max_tokens: int = 2048, timeout: int = 120, is_remote: bool = False, require_confirm: bool = True): self.endpoint = endpoint.rstrip("/") self.model = model self.api_key = api_key self.max_tokens = max_tokens self.timeout = timeout self.is_remote = is_remote self.require_confirm = require_confirm self.confirmed = False self.headers = {"Content-Type": "application/json"} if api_key: self.headers["Authorization"] = f"Bearer {api_key}"python def analyze_image(self, image_path: str, prompt: str) -> dict: # Privacy protection: remote transmission requires confirmation if self.is_remote and self.require_confirm and not self.confirmed: print(f"\n⚠️ Privacy warning: using a remote model sends the photo to a third-party server", file=sys.stderr) print(f" Destination server: {self.endpoint}", file=sys.stderr) print(f" The photo may be stored or analyzed by the third party", file=sys.stderr) print(f" Consider using a local model for sensitive photographs", file=sys.stderr) # Reject remote transfer in non-interactive mode if not sys.stdin.isatty(): raise PermissionError( "Remote transmission requires user confirmation, but the current mode is non-interactive.\n" "Set REQUIRE_REMOTE_CONFIRM=false in configuration to disable this check." ) ...[truncated 5914 chars]- Remediation
View remediation
Remediation Suggestions
- Parse endpoints using
urllib.parse.urlsplit()and permit only explicitly supported schemes. - For a client classified as local, require a loopback destination such as
127.0.0.1,::1, or a hostname that resolves exclusively to loopback addresses. - Do not classify trust based on the configuration field name. Derive whether consent is required from the validated network destination.
- Treat all non-loopback destinations as remote and enforce
PRIVACY_MODE,ALLOW_REMOTE_UPLOAD, andREQUIRE_REMOTE_CONFIRM. - Disable automatic redirects with
allow_redirects=False, or validate every redirect target before sending sensitive request data. - Reject URLs containing embedded credentials, unsupported schemes, ambiguous host representations, or untrusted ports where appropriate.
- Consider an explicit destination allowlist and display the normalized destination before obtaining consent.
- Preserve confirmation in non-interactive Agent use through an explicit per-invocation authorization mechanism rather than silently disabling it.
- Add security tests for:
- Public hosts supplied through
LOCAL_LLM_ENDPOINT - IPv4 and IPv6 loopback addresses
- Hostnames resolving to non-loopback addresses
- Redirects from local to external destinations
- DNS rebinding and mixed-address DNS responses
- Non-interactive invocation
- Each privacy-mode and upload-permission combination
- Public hosts supplied through
- Parse endpoints using
