T09 · Insecure Skill Coding Practices
- Location
scripts/auth_check.sh:13- Finding
Caller-Controlled HTTPS Endpoint Can Receive Retrieved Credentials
- Content
View full analysis
&2; exit 2 ;; esac done ``` ```bash if [[ ! "$URL" =~ ^https:// ]]; then echo "AUTH_ERROR invalid_url=https_required" exit 2 fi ``` ```bash get_key() { local from_env="${!ENV_VAR:-}" if [[ -n "$from_env" ]]; then printf '%s' "$from_env" return 0 fi if [[ -f "$CRED_FILE" ]]; then python3 - "$CRED_FILE" <<'PY' import json, sys p = sys.argv[1] try: d = json.load(open(p, 'r', encoding='utf-8')) except Exception: print('', end='') raise SystemExit(0) for k in ('apiKey', 'api_key', 'token', 'accessToken'): v = d.get(k) if isinstance(v, str) and v.strip(): print(v.strip(), end='') break PY return 0 fi printf '' } KEY="$(get_key || true)" if [[ -z "$KEY" ]]; then echo "AUTH_MISSING service=$SERVICE env=$ENV_VAR cred_file=$CRED_FILE" exit 0 fi STATUS=$(curl -sS -o /dev/null -w "%{http_code}" --max-time "$TIMEOUT" -H "Authorization: Bearer $KEY" "$URL" || true) ``` ### Technical Analysis The script accepts both the credential source and probe URL from its caller. URL validation only verifies that the supplied string starts with `https://`. It does not verify that the destination hostname is associated with the service named by `--service`, nor does it enforce an allowlist of trusted API hosts. After retrieving a token from the caller-selected environment variable or credential file, the script places that token in an `Authorization: Bearer` header and sends it to the supplied URL. HTTPS pr ...[truncated 1670 chars]- Remediation
View remediation
