T09 · Insecure Skill Coding Practices
- Location
plugin.py:21- Finding
Configurable API Endpoint Enables Credential and Source-Code Disclosure
- Content
View full analysis
Dict[str, str]: """Build request headers for the Astrai API.""" headers = { "Authorization": f"Bearer {self.api_key}", "Content-Type": "application/json", "X-Astrai-Task-Type": "code-review", "X-Astrai-Source": "openclaw-skill-code-review", } if self.local_only: headers["X-Astrai-Routing-Mode"] = "local-only" else: headers["X-Astrai-Provider-Keys"] = json.dumps(self.provider_keys) headers["X-Astrai-Available-Providers"] = ",".join( self.provider_keys.keys() ) return headers def _call_astrai( self, system_prompt: str, user_content: str ) -> Dict[str, Any]: """Make a request to the Astrai chat completions API.""" url = f"{ASTRAI_BASE_URL}/chat/completions" headers = self._build_headers() payload = json.dumps({ "messages": [ {"role": "system", "content": system_prompt}, {"role": "user", "content": user_content}, ], "response_format": {"type": "json_object"}, }).encode("utf-8") req = urllib.request.Request( url, data=payload, headers=headers, method="POST" ) try: with urllib.request.urlopen(req, timeout=120) as resp: resp_headers = {k: v for k, v in resp.getheaders()} body = json.loads(resp.read().decode("utf-8")) ``` ### Technical Analysis The destination receiving sensitive requests is taken directly from the undocumented `ASTRAI_BASE_URL` environment variable. The code does not validate its scheme, hostname, port, or trust relationship before attaching sensitive headers and sending the review payload. ...[truncated 2135 chars]- Remediation
View remediation
