T09 · Insecure Skill Coding Practices
- Location
scripts/call_api.py:49- Finding
API Credential Can Be Redirected to an Attacker-Controlled Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/config.py:14-21;scripts/call_api.py:49-67
Vulnerability Type: Configurable credential destination without endpoint validation
Risk Level: HighVulnerable Code
python # scripts/config.py:14-21 model_config = SettingsConfigDict( env_prefix="XBY_GAOKAO_", env_file=".env", env_file_encoding="utf-8", extra="ignore", ) # API configuration base_url: str = "https://mcp.xiaobenyang.com"python # scripts/call_api.py:49-67 url = f"{settings.base_url}/api" mcp_id = mcp_id or settings.mcp_id api_key = get_api_key() if not api_key: raise UpstreamError("API密钥未设置,请先调用 set_api_key()") headers = { "XBY-APIKEY": api_key, "func": tool_name, "mcpid": mcp_id, "Content-Type": "application/json", } t0 = time.time() try: resp = self._session.post( url=url, headers=headers, data=json.dumps(params), timeout=settings.timeout_seconds, )Technical Analysis
SettingsConfigDictallows settings to be overridden through variables using theXBY_GAOKAO_prefix. Consequently,XBY_GAOKAO_BASE_URLcan replace the intended API origin. The client then attaches the user'sXBY-APIKEYcredential to a request sent to that configurable origin.The implementation does not enforce HTTPS, verify that the destination hostname is
mcp.xiaobenyang.com, or apply an explicit endpoint allowlist. It also does not explicitly disable or validate redirects. An actor who controls the launch environment or.envconfiguration can therefore redirect the credential and extraction parameters to an endpoint under their control.Attack Path
- An attacker gains control over the Skill's environment variables or writable
.envconfiguration. - The attacker sets
XBY_GAOKAO_BASE_URLto an attacker-controlled HTTP or HTTPS server. - The user configures a ...[truncated 861 chars]
- An attacker gains control over the Skill's environment variables or writable
- Remediation
View remediation
Remediation Suggestions
- Make the production API endpoint immutable unless endpoint customization is explicitly required.
- If customization is necessary, parse the URL and enforce:
- The
httpsscheme. - An exact hostname allowlist, such as
mcp.xiaobenyang.com. - The expected port and path.
- Rejection of embedded credentials and malformed hostnames.
- The
- Disable automatic redirects for authenticated requests, or validate every redirect destination before resending credentials.
- Separate endpoint selection from secret-bearing request construction so credentials are attached only after origin validation.
- Treat
.envand process-environment configuration as untrusted input. - Add tests proving that HTTP endpoints, lookalike domains, user-information URL tricks, and cross-origin redirects are rejected.
