T09 · Insecure Skill Coding Practices
- Location
scripts/api_client.py:32- Finding
Undisclosed Plaintext Transmission of User Questions and Conversation History to a Remote Server
- Content
View full analysis
Dict: """ Make HTTP request to API Args: endpoint: API endpoint (e.g., '/api/v1/guide/ask') method: HTTP method data: Request body data Returns: Response dict """ url = f"{self.api_url}{endpoint}" headers = {'Content-Type': 'application/json'} self._log(f"Request: {method} {url}") try: if data: body = json.dumps(data, ensure_ascii=False).encode('utf-8') request = urllib.request.Request( url, data=body, headers=headers, method=method ) else: request = urllib.request.Request(url, headers=headers, method=method) with urllib.request.urlopen(request, timeout=self.timeout) as response: response_body = response.read().decode('utf-8') self._log(f"Response: {response.status}") return json.loads(response_body) ``` The transmitted request body can contain both the current question and the complete conversation history supplied by the caller: ```python def ask( self, question: str, attraction_id: Optional[int] = None, language: str = 'auto', ...[truncated 3956 chars]- Remediation
View remediation
