T09 · Insecure Skill Coding Practices
- Location
scripts/search.sh:94- Finding
Search Queries Transmitted over Plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search.sh, lines 94–96
Vulnerability Type: Plaintext transmission of potentially sensitive search data
Risk Level: MediumVulnerable Code
bash search_baidu() { local url="http://www.baidu.com/s?wd=${query}" curl -s -L "$url" -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" 2>/dev/null | \Technical Analysis
The Baidu search function places the URL-encoded user query in an HTTP URL. Baidu is also configured as the default search engine. Consequently, invoking the skill without explicitly selecting another engine causes the initial request, including the complete query string, to be transmitted without transport encryption.
The
-Loption only instructscurlto follow redirects. It does not retroactively secure the initial plaintext request if Baidu redirects the client to HTTPS. An on-path attacker can therefore observe the query or alter the HTTP response before the script processes it. Because the response is transformed withsed,grep, andheadand then presented as search output, attacker-injected content may also be returned to the user or consuming agent.Attack Path
- A user invokes the skill without overriding its default
baidusearch engine. - The script URL-encodes the search query and embeds it in an
http://www.baidu.com/URL. - The initial request and query string cross the network without TLS protection.
- An on-path attacker, compromised gateway, or untrusted network operator intercepts the request.
- The attacker reads the search terms or modifies the plaintext response.
- The script processes and displays the attacker-controlled response content as search output.
Impact Assessment
Exploitation does not directly grant local operating-system privileges or execute code. Its scope is the confidentiality and integrity of searches made through the default Baidu pa ...[truncated 432 chars]
- A user invokes the skill without overriding its default
- Remediation
View remediation
Remediation Suggestions
Replace the plaintext endpoint with HTTPS:
bash local url="https://www.baidu.com/s?wd=${query}"Restrict both initial requests and redirects to HTTPS, and make HTTP failures explicit:
bash curl --fail-with-body --silent --show-error --location \ --proto '=https' --proto-redir '=https' \ "$url" \ -H "User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"Do not suppress all error output with
2>/dev/null, because doing so conceals TLS, redirect, and connection failures that may be relevant to security. Apply the HTTPS-only protocol restrictions consistently to every search-engine request and add a regression test that rejects allhttp://search endpoints.
