T09 · Insecure Skill Coding Practices
- Location
main.py:80- Finding
Arbitrary LLM Endpoint Can Receive API Credentials and Financial Document Content
- Content
View full analysis
Vulnerability Details
File Location:
main.py, lines 80–133
Vulnerability Type: Unvalidated external service endpoint and sensitive-data disclosure
Risk Level: HighVulnerable Code
python api_key = os.getenv("LLM_API_KEY") api_base = os.getenv("LLM_API_BASE", "https://api.deepseek.com/v1") model_name = os.getenv("LLM_MODEL", "deepseek-chat") provider = os.getenv("LLM_PROVIDER", "deepseek").lower() # Provider specific default configurations if provider == "siliconflow" or provider == "硅基流动": # SiliconFlow default if not os.getenv("LLM_API_BASE"): api_base = "https://api.siliconflow.cn/v1" if not os.getenv("LLM_MODEL"): model_name = "deepseek-ai/DeepSeek-V3" # Common model on SiliconFlow elif provider == "qwen" or provider == "dashscope" or provider == "通义千问": # DashScope (Aliyun) default - usually requires compatible OpenAI client or specific URL # Here we assume using OpenAI-compatible endpoint if available, or user sets BASE_URL if not os.getenv("LLM_API_BASE"): api_base = "https://dashscope.aliyuncs.com/compatible-mode/v1" if not os.getenv("LLM_MODEL"): model_name = "qwen-plus" if not api_key: log_cb("Skipping LLM analysis: LLM_API_KEY environment variable not set.") return None headers = { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json" } data = { "model": model_name, "messages": [ {"role": "system", "content": "You are a helpful assistant that extracts data into JSON."}, {"role": "user", "content": prompt} ], "temperature": 0.1, "response_format": {"type": "json_object"} } try: response = requests.post(f"{api_base}/chat/completions", headers=headers, json=data, timeout=120) response.raise_for_status() result = response.json() content = result['choices'][0]['message']['content']The
prompttransmitted in this request includes the following raw document excerpt:`` ...[truncated 2197 chars]
- Remediation
View remediation
Remediation Suggestions
- Allowlist the documented provider endpoints and bind each endpoint to its corresponding provider:
api.deepseek.comapi.siliconflow.cndashscope.aliyuncs.com
- Parse the endpoint with a standard URL parser and reject:
- Schemes other than HTTPS
- Embedded usernames or passwords
- Unexpected ports
- IP-literal destinations
- Loopback, link-local, private, and reserved network addresses
- Hosts not associated with the selected provider
- Require a separate, explicit unsafe opt-in before permitting custom endpoints. Display the destination and explain that credentials and document contents will be transmitted.
- Associate credentials with specific providers instead of using one generic bearer token for arbitrary destinations.
- Redact or minimize document content before transmission. Extract only necessary fields locally where feasible.
- Add an explicit data-processing disclosure identifying what content is sent, the destination provider, and applicable retention implications.
- Avoid logging response bodies because provider responses may reproduce sensitive document content.
- Add automated tests confirming that hostile schemes, private addresses, redirects to untrusted hosts, and unapproved domains are rejected.
- Allowlist the documented provider endpoints and bind each endpoint to its corresponding provider:
