T09 · Insecure Skill Coding Practices
- Location
scripts/cli.mjs:24- Finding
Unrestricted CLI Parameters Are Forwarded to External Services
- Content
View full analysis
Object.entries(p) .filter(([, v]) => v != null) .map(([k, v]) => `${encodeURIComponent(k)}=${encodeURIComponent(v)}`) .join('&'); ``` ```js const COMMANDS = { search: (p) => ({ url: `https://web3.binance.com/bapi/defi/v5/public/wallet-direct/buw/wallet/market/token/search/ai?${qs(p)}`, }), meta: (p) => ({ url: `https://web3.binance.com/bapi/defi/v1/public/wallet-direct/buw/wallet/dex/market/token/meta/info/ai?${qs(p)}`, }), dynamic: (p) => ({ url: `https://web3.binance.com/bapi/defi/v4/public/wallet-direct/buw/wallet/market/token/dynamic/info/ai?${qs(p)}`, }), kline: (p) => { // Translate unified interface → upstream kline field names. // { chainId, contractAddress, interval, ... } → { platform, address, interval, ... } const { chainId, contractAddress, ...rest } = p; const platform = chainId == null ? undefined : CHAIN_ID_TO_PLATFORM[chainId]; if (chainId != null && platform === undefined) { const supported = Object.keys(CHAIN_ID_TO_PLATFORM).map((k) => `"${k}"`).join(', '); throw Object.assign( new Error(`kline: unsupported chainId "${chainId}". Supported: ${supported}`), { exitCode: 1 }, ); } const upstream = { ...rest }; if (platform !== undefined) upstream.platform = platform; if (contractAddress !== undefined) upstream.address = contractAddress; return { url: `https://dquery.sintral.io/u-kline/v1/k-line/candles?${qs(upstream)}`, }; }, }; ``` ### Technical Analysis The CLI accepts an arbitrary JSON object and serializes every non-null property into an outbound URL query string. It does not enforce the documented parameter allowlists for any command. For `search`, `meta`, and `dynami ...[truncated 2694 chars]- Remediation
View remediation
