T09 · Insecure Skill Coding Practices
- Location
scripts/memory_rag.py:53- Finding
Agent Memory and Search Queries Can Be Sent to an Arbitrary Plaintext HTTP Endpoint
- Content
View full analysis
List[float]: """Generates embedding vector from Ollama API.""" url = f"{self.ollama_host.rstrip('/')}/api/embeddings" data = json.dumps({"model": self.embedding_model, "prompt": text}).encode('utf-8') req = urllib.request.Request( url, data=data, headers={'Content-Type': 'application/json'} ) try: with urllib.request.urlopen(req, timeout=30) as response: res_data = json.loads(response.read().decode('utf-8')) embedding = res_data.get("embedding") if not embedding: raise ValueError("Empty embedding returned by Ollama server") return embedding except Exception as e: raise RuntimeError(f"Failed to fetch embeddings from Ollama model '{self.embedding_model}': {e}") ``` The method is called with indexed memory chunks and search queries: ```python embedding = self._get_embedding(chunk) ``` ```python query_emb = self._get_embedding(query) ``` ### Technical Analysis The embedding server URL is taken directly from the `OLLAMA_HOST` environment variable. The implementation does not validate the destination host, restrict requests to loopback interfaces, enforce HTTPS for remote destinations, or require explicit authorization before transmitting content. During indexing, the text sent to this endpoint originates from persistent agent memory files. During semantic search, the user's query is also sent. Both data types can contain private conversations, personal information, operational context, or credentials that the limited sanitizer ...[truncated 1254 chars]- Remediation
View remediation
