T09 · Insecure Skill Coding Practices
- Location
push.py:105- Finding
Aligenie credentials and private broadcast content are transmitted over plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
push.py:105-122; insecure endpoint configuration is documented inSKILL.md:42-49andDEPLOY.md:98-107
Vulnerability Type: Sensitive information transmitted without transport encryption
Risk Level: CriticalVulnerable Code
python payload = { "appId": _app_id or "", "appSecret": _app_secret or "", "openId": _open_id, "text": text, "deviceType": device_type, } _LOGGER.info(f"[Aligenie Push] 发送播报请求: {text[:50]}...") try: loop = asyncio.get_event_loop() response = await loop.run_in_executor( None, lambda: requests.post( _push_server, json=payload, headers={"Content-Type": "application/json"}, timeout=15, ) )The documented configuration explicitly uses plaintext HTTP:
text ALIGENIE_PUSH_SERVER=http://你的云服务器公网IP:58472/push ALIGENIE_APP_ID=2026032918608 ALIGENIE_APP_SECRET=审批通过后获取 ALIGENIE_DEVICE_OPEN_ID=天猫精灵设备openIdTechnical Analysis
The client sends the Aligenie AppSecret, AppId, device openId, and full broadcast message to a configurable relay server. The implementation does not require HTTPS, validate the URL scheme, pin a trusted relay identity, or authenticate the server at the application layer.
The deployment guide instructs operators to use a public IP over HTTP, despite the architecture diagram describing the connection as HTTPS. Consequently, the intended deployment exposes credentials and potentially private notification content to passive network monitoring and active man-in-the-middle attacks.
Sending the AppSecret to the relay on every push also exceeds the minimum data transfer necessary. The relay can retain the credentials securely and accept an independently authenticated push request that contains only the message and an authorized device alias.
Attack Path
- The operator follows the documented configuration and uses
http://public-server:58472/push...[truncated 1020 chars]
- The operator follows the documented configuration and uses
- Remediation
View remediation
Remediation Suggestions
- Require an
https://relay URL and reject plaintext HTTP except for explicitly enabled loopback-only development configurations. - Deploy the relay behind a correctly configured TLS reverse proxy with a valid certificate and modern TLS settings.
- Keep the Aligenie AppSecret exclusively on the relay server. Do not include it in routine client push payloads.
- Authenticate client-to-relay requests with a separate, revocable credential or signed request protocol.
- Bind each client identity to a server-side allowlist of device identifiers instead of accepting arbitrary
openIdvalues. - Protect configuration secrets with an operating-system secret store or restricted environment injection rather than plaintext workspace documentation.
- Rotate the AppSecret and relay credentials after migrating from HTTP because previously transmitted credentials must be considered exposed.
- Correct
SKILL.mdandDEPLOY.mdso all production examples use HTTPS.
- Require an
