T09 · Insecure Skill Coding Practices
- Location
skills/aida/index.js:3- Finding
Bearer Credential Can Be Transmitted to an Unrestricted Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
skills/aida/index.js:3-4, 26-31
Vulnerability Type: Unrestricted transmission of sensitive credentials
Risk Level: HighVulnerable Code
js const API = process.env.AIDA_API_URL; const KEY = process.env.AIDA_API_KEY; async function call(path, fallback) { try { const res = await fetch(API + path, { headers: { 'Authorization': `Bearer ${KEY}`, 'Content-Type': 'application/json' } });Technical Analysis
The destination URL is taken directly from the
AIDA_API_URLenvironment variable without URL parsing, HTTPS enforcement, host validation, or an origin allowlist. The Skill then sends the sensitiveAIDA_API_KEYvalue to that destination in anAuthorizationheader.Authentication with the legitimate AIDA service is necessary for the declared functionality. However, allowing the credential destination to be any configured URL exceeds least privilege. A configuration modification could direct the request to a plaintext HTTP endpoint or an attacker-controlled server. Redirect behavior is also not restricted or validated by the Skill.
Attack Path
- An attacker, compromised deployment process, or configuration error changes
AIDA_API_URLto an attacker-controlled endpoint. - A user invokes any supported AIDA intent, such as
aida.status. - The Skill constructs a URL from the unvalidated environment value and the selected path.
- The request sends
Authorization: Bearer <AIDA_API_KEY>to the configured server. - The recipient captures the bearer credential and can reuse it until it expires or is revoked.
Impact Assessment
Successful exploitation discloses the complete AIDA bearer token. The attacker obtains whatever privileges are assigned to that token, potentially including access to live building status, diagnostics, optimization functions, or device controls. The exact scope d ...[truncated 87 chars]
- An attacker, compromised deployment process, or configuration error changes
- Remediation
View remediation
Remediation Suggestions
- Parse the configured endpoint with
new URL()before issuing requests. - Require HTTPS and reject all non-HTTPS protocols.
- Enforce an explicit allowlist of trusted AIDA hostnames and ports.
- Construct request URLs using the URL API rather than string concatenation.
- Disable redirects where possible, or validate every redirect destination before forwarding authorization headers.
- Use a narrowly scoped token limited to the specific operations required by the Skill.
- Apply token expiration, rotation, revocation, and audit logging.
- Fail closed when the endpoint is missing, malformed, or outside the trusted origin.
- Never include the bearer token in error messages or application logs.
- Parse the configured endpoint with
