T09 · Insecure Skill Coding Practices
- Location
scripts/hot_scanner.py:111- Finding
API Credential Can Be Redirected to an Arbitrary Network Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/hot_scanner.py, lines 111–116 and 146–154
Vulnerability Type: Unvalidated authentication endpoint configuration
Risk Level: HighVulnerable Code
python def get_client() -> OpenAI: api_key = os.environ.get("AISA_API_KEY") if not api_key: print("❌ Error: AISA_API_KEY environment variable is not set.", file=sys.stderr) print(" Set it with: export AISA_API_KEY=your_key_here", file=sys.stderr) sys.exit(1) base_url = os.environ.get("AISA_BASE_URL", "https://api.aisa.one/v1") return OpenAI(api_key=api_key, base_url=base_url)The resulting client is later used to send an authenticated request:
python response = client.chat.completions.create( model=model, messages=[ {"role": "system", "content": SYSTEM_PROMPT}, {"role": "user", "content": prompt}, ], temperature=0.2, )Technical Analysis
The application reads the sensitive
AISA_API_KEYcredential from the environment but independently obtains the destination from the unrestrictedAISA_BASE_URLenvironment variable. No URL scheme, hostname, port, or destination allowlist validation is performed.The OpenAI-compatible client uses the configured API key to authenticate requests sent to the configured base URL. Consequently, a party capable of influencing the scanner's environment can set
AISA_BASE_URLto an attacker-controlled service. When the scanner makes its completion request, the authentication credential can be exposed to that service.Network access and transmission of the API key to the legitimate AISA API are necessary for the declared live market-scanning functionality. Allowing an arbitrary destination is not necessary for that functionality and exceeds least-privilege configuration requirements.
Attack Path
- An attacker gains the ability to influence the environment used t ...[truncated 1309 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove support for
AISA_BASE_URLif custom endpoints are not essential and use a constant trusted endpoint:python base_url = "https://api.aisa.one/v1" - If endpoint customization is required, validate the parsed URL against an explicit allowlist of trusted HTTPS hostnames.
- Reject plaintext HTTP, embedded URL credentials, unexpected ports, IP-address destinations, and URLs whose normalized hostname is not explicitly trusted.
- Do not reuse
AISA_API_KEYwith custom endpoints. Require a separate, clearly named credential for non-production or custom servers. - Fail closed when endpoint validation fails and avoid including credential values in errors or logs.
- Document every supported endpoint override and warn that custom endpoints receive authentication material and request contents.
- Where supported, use narrowly scoped, revocable API credentials with usage limits and monitor for unexpected destinations or consumption.
- Remove support for
