T09 · Insecure Skill Coding Practices
- Location
scripts/create-player.mjs:285- Finding
Unvalidated Remote Endpoints Permit Plaintext Disclosure and Server-Side Request Forgery
- Content
View full analysis
Vulnerability Details
File Location:
scripts/create-player.mjs:285-286, 371-375; insecure HTTP endpoint example inSKILL.md:99-105, 123-124
Vulnerability Type: Unrestricted user-controlled network destinations and plaintext transmission
Risk Level: HighVulnerable code:
js const reactorApi = args.reactorApi.replace(/\/+$/, ''); const guildApi = args.guildApi.replace(/\/+$/, ''); signupResponse = await fetch(`${guildApi}/auth/signup`, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify(signupPayload) });The documentation also presents a plaintext endpoint:
json { "guild": { "id": "0-1", "name": "Orbital Hydro", "tag": "OH", "services": { "guild_api": "http://crew.oh.energy/api/", "reactor_api": "https://public.testnet.structs.network/", "client_websocket": "wss://public.testnet.structs.network:26657/websocket" } } }Technical Analysis
The script accepts
--guild-apiand--reactor-apias arbitrary strings and uses them as network destinations after only removing trailing slashes. It does not enforce HTTPS, validate hostnames against an allowlist or trusted on-chain guild record, reject embedded credentials, restrict redirects, or prevent access to loopback, link-local, private-network, and cloud metadata addresses.The guild signup request transmits the wallet address, public key, join signature, guild identifier, username, profile image reference, and optional rendering attributes. Although it does not transmit the mnemonic or private key, the signature is credential-like proof generated with the private key. Sending this information over HTTP allows a network-positioned attacker to observe or alter the request and response.
The unrestricted URL behavior also creates a server-side request forgery primitive in environments where the Agent can reach resources unavaila ...[truncated 1958 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse endpoints with
new URL()and permit onlyhttps:in normal operation. Remove plaintext HTTP examples fromSKILL.md. - Verify the guild endpoint against the authoritative on-chain guild record before submitting any signed data.
- Require explicit user approval for destinations outside a narrowly defined trusted-host allowlist.
- Resolve destination hostnames and reject loopback, link-local, private, multicast, reserved, and cloud metadata address ranges for both IPv4 and IPv6. Repeat validation after DNS resolution and on every redirect.
- Disable redirects or limit them to validated HTTPS destinations on the same trusted host.
- Add bounded connection and response timeouts, response-size limits, and strict JSON schema validation.
- Display the final normalized destination and the exact categories of data being submitted before signing or sending the request.
- Consider binding the intended endpoint, guild identifier, nonce, and expiration into the signed protocol so signatures cannot be replayed outside their intended context.
- Parse endpoints with
