T09 · Insecure Skill Coding Practices
- Location
scripts/dividends.py:121- Finding
Configurable HTTPS Endpoint Can Receive the AIsa API Key
- Content
View full analysis
Vulnerability Details
File Location:
scripts/dividends.py, lines 121–130 and 219–227
Vulnerability Type: Unrestricted credential forwarding to a configurable network endpoint
Risk Level: MediumVulnerable Code
python def get_client() -> OpenAI: api_key = os.environ.get("AISA_API_KEY") if not api_key: print("❌ Error: AISA_API_KEY environment variable is not set.", file=sys.stderr) print(" Set it with: export AISA_API_KEY=your_key_here", file=sys.stderr) sys.exit(1) base_url = os.environ.get("AISA_BASE_URL", DEFAULT_AISA_BASE_URL).strip().rstrip("/") if not base_url.startswith("https://"): print("❌ Error: AISA_BASE_URL must use https:// when provided.", file=sys.stderr) sys.exit(1) return OpenAI(api_key=api_key, base_url=base_url)The configured client subsequently makes the authenticated request:
python response = client.chat.completions.create( model=model, messages=[ {"role": "system", "content": SYSTEM_PROMPT}, {"role": "user", "content": prompt}, ], temperature=0.1, **response_kwargs, )Technical Analysis
The Skill accepts an arbitrary
AISA_BASE_URLand verifies only that its string begins withhttps://. This enforces encrypted transport but does not establish that the destination is operated by AIsa or otherwise trusted.The
OpenAIclient is initialized with both the environment-provided endpoint andAISA_API_KEY. Authenticated requests are therefore sent to whichever HTTPS host the configuration identifies. An attacker who can influence the runtime environment can substitute an attacker-controlled HTTPS endpoint and collect the authentication credential and submitted ticker-analysis prompts.Network access is necessary for the Skill's declared API-backed dividend-analysis functionality. Sending the credential to the default
https://api.aisa.one/v1endpoint is consistent with that purpose. Allowing the sa ...[truncated 1722 chars]- Remediation
View remediation
Remediation Suggestions
-
Allowlist the official API host by default. Parse the endpoint structurally and require the normalized hostname to equal
api.aisa.one.python from urllib.parse import urlparse raw_base_url = os.environ.get( "AISA_BASE_URL", DEFAULT_AISA_BASE_URL, ).strip().rstrip("/") parsed = urlparse(raw_base_url) if ( parsed.scheme != "https" or parsed.hostname != "api.aisa.one" or parsed.username is not None or parsed.password is not None or parsed.fragment ): print("Error: AISA_BASE_URL must use the trusted api.aisa.one HTTPS endpoint.", file=sys.stderr) sys.exit(1) -
Do not forward the AIsa credential to third-party compatible endpoints. If custom endpoints are a required feature, use a separate variable such as
CUSTOM_API_KEYand never reuseAISA_API_KEYoutside the official AIsa host. -
Require explicit opt-in for custom endpoints. Display the normalized destination hostname and require an affirmative configuration flag before transmitting credentials.
-
Reject ambiguous URLs. Disallow URL user information, malformed hosts, unexpected ports, fragments, and redirects to untrusted hosts. Ensure redirect handling cannot forward authorization headers across origins.
-
Apply server-side key restrictions. Where supported, scope keys to the minimum required API operations, enforce short expiration periods, limit usage quotas, and restrict keys to expected clients or origins.
-
Avoid exposing secrets in diagnostics. Continue not printing the credential, and ensure SDK debug logging and exception handling cannot include authorization headers.
-
Document the trust boundary clearly. Warn that endpoint configuration controls where credentials and query content are transmitted, rather than stating only that the URL should point to a trusted endpoint.
-
