T09 · Insecure Skill Coding Practices
- Location
scripts/analyze_stock.py:106- Finding
API Credential and Query Redirection Through an Unrestricted Endpoint Override
- Content
View full analysis
OpenAI: api_key = os.environ.get("AISA_API_KEY") if not api_key: print("❌ Error: AISA_API_KEY environment variable is not set.", file=sys.stderr) print(" Set it with: export AISA_API_KEY=your_key_here", file=sys.stderr) sys.exit(1) base_url = os.environ.get("AISA_BASE_URL", "https://api.aisa.one/v1") return OpenAI(api_key=api_key, base_url=base_url) ``` The configured client subsequently transmits an authenticated request: ```python response = client.chat.completions.create( model=model, messages=[ {"role": "system", "content": SYSTEM_PROMPT}, {"role": "user", "content": prompt}, ], temperature=0.1, ) ``` ### Technical Analysis The `AISA_BASE_URL` environment variable completely controls the destination used by the OpenAI-compatible client. The value is not validated to ensure that it uses HTTPS or belongs to an approved host. The client is initialized with `AISA_API_KEY`, so requests to the configured destination are authenticated using that credential. The request body also includes the generated analysis prompt and user-supplied ticker symbols. Consequently, an actor capable of modifying the process environment can redirect sensitive authenticated traffic to an attacker-controlled endpoint. Network communication with the default AISA service is necessary for the Skill's declared live-analysis functionality. However, allowing unrestricted destination replacement exceeds the minimum privilege required when only the official AISA endpoint is intended. ### Attack Path 1. An attacker gains control over the environment used to launch the Skill, such as through a poisoned wrapper script, CI co ...[truncated 1178 chars]- Remediation
View remediation
