T09 · Insecure Skill Coding Practices
- Location
scripts/ima_create.py:1605- Finding
Unrestricted API Base URL Allows Bearer Credential Exfiltration
- Content
View full analysis
dict: return { "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", "x-app-source": "ima_skills", "x_app_language": language, } ``` ```python p.add_argument("--base-url", default=DEFAULT_BASE_URL, help="API base URL") ``` ```python def main(): args = build_parser().parse_args() base = args.base_url apikey = args.api_key ``` The resulting user-controlled base URL is subsequently used for authenticated requests: ```python url = f"{base_url}/open/v1/product/list" params = {"app": app, "platform": platform, "category": category} headers = make_headers(api_key, language) resp = requests.get(url, params=params, headers=headers, timeout=30) ``` ```python url = f"{base_url}/open/v1/tasks/create" headers = make_headers(api_key) resp = requests.post(url, json=payload, headers=headers, timeout=30) ``` ### Technical Analysis The `--base-url` command-line option accepts an arbitrary URL and is used directly as the origin for API requests. These requests include the IMA API key in an `Authorization: Bearer ...` header. There is no validation that the supplied URL: - Uses HTTPS. - Resolves to the documented `api.imastudio.com` service. - Belongs to an approved hostname allowlist. - Retains the expected origin after redirects. Consequently, any party able to influence the Skill's invocation arguments can redirect authenticated traffic to an attacker-controlled server. This behavior exceeds the documented minimum network privilege, which states that the credential is sent to IMA-owned endpoints. The issue does not require command injection or local code execution. The le ...[truncated 1788 chars]- Remediation
View remediation
