T09 · Insecure Skill Coding Practices
- Location
scripts/hot_scanner.py:111- Finding
Authenticated API Requests Can Be Redirected to an Arbitrary Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/hot_scanner.py, lines 106–112 and 152–160
Vulnerability Type: Unrestricted authenticated endpoint configuration
Risk Level: MediumVulnerable Code
python def get_client() -> OpenAI: api_key = os.environ.get("AISA_API_KEY") if not api_key: print("❌ Error: AISA_API_KEY environment variable is not set.", file=sys.stderr) print(" Set it with: export AISA_API_KEY=your_key_here", file=sys.stderr) sys.exit(1) base_url = os.environ.get("AISA_BASE_URL", "https://api.aisa.one/v1") return OpenAI(api_key=api_key, base_url=base_url)The resulting client is subsequently used to issue an authenticated request:
python try: response = client.chat.completions.create( model=model, messages=[ {"role": "system", "content": SYSTEM_PROMPT}, {"role": "user", "content": prompt}, ], temperature=0.2, )Technical Analysis
The
AISA_BASE_URLenvironment variable fully controls the destination of the OpenAI-compatible client. The value is not validated against an allowlist, is not restricted to HTTPS, and is not documented as a required configuration option inSKILL.md.When
client.chat.completions.create()is called, the client sends theAISA_API_KEYas authentication material to the configured endpoint. Consequently, an attacker who can influence the process environment can redirect the authenticated request to an attacker-controlled server and capture the credential.Allowing arbitrary endpoint selection exceeds the minimum privilege required for the declared functionality, which only needs to communicate with the AISA API at
https://api.aisa.one/v1. Transmission of the key to that default service is necessary and expected; the vulnerability is the unrestricted ability to change the credential recipient.Attack Path
- An attacker compromises a launcher, wrapper script, shell pr ...[truncated 1486 chars]
- Remediation
View remediation
Remediation Suggestions
-
Use a fixed production endpoint
python return OpenAI( api_key=api_key, base_url="https://api.aisa.one/v1", )This is the safest option when alternate endpoints are not required.
-
Apply a strict allowlist if endpoint customization is necessary
- Parse the URL with
urllib.parse.urlparse. - Require the
httpsscheme. - Require an exact approved hostname, such as
api.aisa.one. - Reject embedded credentials, unexpected ports, fragments, and malformed URLs.
- Avoid suffix-only hostname checks that could accept domains such as
api.aisa.one.attacker.example.
- Parse the URL with
-
Make endpoint overrides explicit
- Prefer a documented command-line or configuration option over an undocumented environment variable.
- Display the selected non-default endpoint and require explicit user confirmation before sending credentials.
-
Control redirect behavior
- Ensure authorization headers are never forwarded when a redirect changes the origin.
- Reject redirects to hosts outside the allowlist.
-
Reduce credential exposure
- Use a narrowly scoped API key with minimal permissions and spending limits.
- Rotate the key if execution with an untrusted
AISA_BASE_URLmay already have occurred. - Avoid logging authorization headers or including keys in exception output.
-
