T09 · Insecure Skill Coding Practices
- Location
scripts/run.py:24- Finding
Configurable API Endpoint Can Expose Credentials and Submitted Data
- Content
View full analysis
Vulnerability Details
File Location:
scripts/run.py:24-35, 65-75
Vulnerability Type: Unrestricted credential-bearing outbound requests
Risk Level: Mediumpython def build_base_url(): return os.getenv("AISKILLS_BASE_URL", DEFAULT_BASE_URL).rstrip("/") def build_headers(): api_key = os.getenv("AISKILLS_API_KEY", "").strip() tenant_id = os.getenv("AISKILLS_TENANT_ID", "default").strip() or "default" if not api_key: fail("AISKILLS_API_KEY is required") return { "Content-Type": "application/json", # Cloudflare blocks urllib's default Python user agent for this endpoint. "User-Agent": "ai-skills-runner/1.0 (+https://ai-skills.ai)", "Accept": "application/json", "X-API-Key": api_key, "X-Tenant-Id": tenant_id, } def request_json(method, path, payload): body = None if payload is None else json.dumps(payload).encode("utf-8") req = urllib.request.Request( f"{build_base_url()}{path}", data=body, method=method, headers=build_headers(), ) try: with urllib.request.urlopen(req, context=SSL_CONTEXT) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
AISKILLS_BASE_URLcompletely controls the destination receiving API requests, but the value is not restricted to HTTPS and its hostname is not validated against a trusted allowlist. Every request to this destination is automatically supplied withX-API-KeyandX-Tenant-Id.Consequently, a party that can influence the runner's environment can direct requests to an attacker-controlled server or to a plaintext HTTP endpoint. The request bodies can also contain the user-provided Kuaishou link, parsed content information, and task creation data. The use of an SSL context only protects HTTPS requests; it does not prevent an
http://base URL. Redirect beha ...[truncated 1933 chars]- Remediation
View remediation
Remediation Suggestions
- Parse the configured base URL with
urllib.parse.urlsplit()and reject every scheme excepthttps. - Restrict the hostname to
ai-skills.aiand explicitly approved subdomains, or require administrators to maintain a narrowly scoped trusted-host allowlist. - Reject URLs containing user information, fragments, unexpected ports, or ambiguous hostname encodings.
- Disable automatic redirects for authenticated requests or implement a redirect handler that permits only HTTPS redirects to the same approved origin.
- Never forward
X-API-KeyorX-Tenant-Idacross an origin change. - Validate the base URL once during startup and fail closed before reading or using the API key.
- Protect environment and deployment configuration from untrusted modification and document that custom endpoints receive authentication credentials.
- Use narrowly scoped, revocable API keys and rotate any credential that may have been used with an untrusted endpoint.
- Parse the configured base URL with
