T09 · Insecure Skill Coding Practices
- Location
tessie.sh:9- Finding
Bearer Credential Disclosure Through an Unrestricted API Endpoint Override
- Content
View full analysis
Vulnerability Details
File Location:
tessie.sh:9andtessie.sh:86-99
Vulnerability Type: Arbitrary credential transmission destination
Risk Level: HighVulnerable Code
bash # Configuration from env or fallback TESSIE_API_URL="${TESSIE_API_URL:-https://api.tessie.com}" TESSIE_API_KEY="${TESSIE_API_KEY:-}"bash # Helper: Make API request api_request() { local method="$1" local endpoint="$2" local data="${3:-}" if [[ -n "$data" ]]; then curl -s --fail --max-time 30 \ -H "Authorization: Bearer $TESSIE_API_KEY" \ -H "Content-Type: application/json" \ -d "$data" \ "${TESSIE_API_URL}${endpoint}" 2>/dev/null else curl -s --fail --max-time 30 \ -H "Authorization: Bearer $TESSIE_API_KEY" \ "${TESSIE_API_URL}${endpoint}" 2>/dev/null fi }Technical Analysis
The destination receiving the Tessie bearer credential is controlled by the
TESSIE_API_URLenvironment variable. The script does not validate the URL scheme, hostname, port, or presence of URL user information before attaching theAuthorizationheader.Although the default destination is the legitimate HTTPS endpoint
https://api.tessie.com, a modified runtime environment can redirect every API request to an arbitrary server. Anhttp://value can additionally cause the credential and request metadata to be transmitted without TLS.Network communication with Tessie is necessary for the declared functionality. Allowing an unrestricted destination override is not necessary and exceeds the minimum privilege required. This also contradicts the assertion in
SECURITY_AUDIT.mdthat HTTPS is enforced.Attack Path
- An attacker gains influence over the environment used to launch the Skill, such as a wrapper, automation configuration, inherited process environment, or deployment setting.
...[truncated 1292 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the
TESSIE_API_URLoverride if alternate API hosts are not an explicit requirement:bash readonly TESSIE_API_URL="https://api.tessie.com" -
If configurability is required, strictly allowlist the exact production origin before making any request:
bash TESSIE_API_URL="${TESSIE_API_URL:-https://api.tessie.com}" if [[ "$TESSIE_API_URL" != "https://api.tessie.com" ]]; then echo "Unsupported Tessie API endpoint" >&2 exit 1 fi -
Reject non-HTTPS schemes, URL user information, unexpected ports, redirects to untrusted hosts, and malformed URLs.
-
Add curl hardening controls:
bash curl --silent --show-error --fail --max-time 30 \ --proto '=https' \ --tlsv1.2 \ -H "Authorization: Bearer $TESSIE_API_KEY" \ -- "${TESSIE_API_URL}${endpoint}" -
If redirects are enabled in the future, ensure authorization headers cannot be forwarded to another origin.
-
Add automated tests verifying that HTTP URLs, lookalike domains, alternate ports, user-information URLs, and arbitrary hosts are rejected before the authorization header is transmitted.
-
Revoke and rotate any Tessie credential that may have been used while an untrusted
TESSIE_API_URLvalue was present.
-
