T09 · Insecure Skill Coding Practices
- Location
scripts/mask.py:45- Finding
Custom API configuration permits transmission of PII and credentials over cleartext HTTP
- Content
View full analysis
MAX_TEXT_BYTES: fail_config( f"Text exceeds {MAX_TEXT_BYTES} bytes. Split into chunks " "(e.g. by paragraph) and call mask.py per chunk." ) payload = json.dumps({"text": text}).encode("utf-8") req = urllib.request.Request( f"{api_url}/v1/anonymize", data=payload, headers={ "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", "User-Agent": "brikko-pii-skill/0.1.0", }, method="POST", ) ``` The same weakness is present in `scripts/restore.py`: ```python api_url = os.environ.get("BRIKKO_API_URL", DEFAULT_API_URL).rstrip("/") text = sys.stdin.read() if not text: fail_config("stdin is empty — pipe LLM response to restore.py") payload = json.dumps( {"text": text, "mapping_id": args.mapping_id} ).encode("utf-8") req = urllib.request.Request( f"{api_url}/v1/restore", data=payload, headers={ "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", "User-Agent": "brikko-pii-skill/0.1.0", }, method="POST", ) ``` ### Technical Analysis The default endpoint is HTTPS, but the `BRIKKO_API_URL` environment variable is accepted without validating its scheme, hostname, or network destination. Consequently, the scripts permit an arbitrary remote `http://` endpoint. The masking request includes the original, unmasked stdin and a bearer API key. The data can contain names, passport details, tax identifier ...[truncated 2114 chars]- Remediation
View remediation
