T09 · Insecure Skill Coding Practices
- Location
examples/config.example.json:2- Finding
Bearer API Credentials and Media Metadata Transmitted Over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
examples/config.example.json:2;scripts/index.js:180-199
Vulnerability Type: Plaintext transmission of credentials and sensitive metadata
Risk Level: HighVulnerable Code
examples/config.example.json:2:json "api_base_url": "http://43.137.46.105:8787",scripts/index.js:180-199:js async request(method, endpoint, body) { const url = new URL(endpoint.replace(/^\//, ''), this.baseUrl); const controller = new AbortController(); const timer = setTimeout(() => controller.abort(), this.timeoutMs); try { const response = await fetch(url, { method, headers: { 'content-type': 'application/json', 'authorization': `Bearer ${this.apiKey}`, 'user-agent': 'davinci-auto-editor/0.2.0' }, body: body === undefined ? undefined : JSON.stringify(body), signal: controller.signal }); const text = await response.text(); const parsed = text ? JSON.parse(text) : {};Technical Analysis
The example configuration directs users to an API endpoint using unencrypted HTTP and a bare IP address. The API client accepts this URL without validating that the protocol is HTTPS. It then transmits the configured API key in a bearer authorization header and serializes request data into the HTTP body.
Because HTTP provides neither confidentiality nor server authentication, an attacker with a network position can inspect or modify this traffic. Relevant attacker positions include a compromised Wi-Fi access point, malicious proxy, local network adversary, or compromised upstream router. The use of an
Authorization: Bearerheader means interception directly discloses a reusable credential.The same channel carries media inventory information and cloud editing requests. A man-in-the-middle attacker could therefore obtain both credentials and private project metadata, inject a fo ...[truncated 1417 chars]
- Remediation
View remediation
Remediation Suggestions
- Enforce HTTPS during configuration validation:
js const apiUrl = new URL(config.api_base_url); if (apiUrl.protocol !== 'https:') { throw new Error('api_base_url must use HTTPS'); } - Permit plaintext HTTP only through an explicit development-only option restricted to loopback addresses such as
127.0.0.1orlocalhost. - Replace the example endpoint with a trusted HTTPS URL under a verified domain.
- Do not recommend bare-IP endpoints unless certificate identity and ownership can be securely verified.
- Rotate any API key that has already been sent to the documented HTTP endpoint.
- Apply narrowly scoped permissions, short expiration periods, revocation support, and server-side rate limits to API keys.
- Consider certificate pinning or equivalent endpoint verification where the deployment threat model requires protection from compromised trust infrastructure.
- Enforce HTTPS during configuration validation:
